Junglewise Threat Intelligence

CVE-2026-64330: Linux Kernel out-of-bounds read in USB Type-C TCPM

CVE-2026-64330 · Severity: info · CVSS 0 · Published 2026-07-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's USB Type-C connector manager could allow a malicious USB device to manipulate how it is identified by the system. By exploiting a lack of boundary checks when processing USB data, a connected device can force the system to register incorrect hardware profiles. This could lead to unauthorized hardware interactions or unexpected system behavior when a malicious device is physically plugged in.

Technical details

An out-of-bounds read exists in the Linux kernel's USB Type-C Port Manager (TCPM) within the svdm_consume_modes() function. The root cause is a failure to validate the 'svid_index' before using it to access the 'pmdata->svids' array. A malicious USB partner device can drive the index beyond the maximum allowed value (SVID_DISCOVERY_MAX), causing the kernel to read from adjacent memory fields in 'struct tcpm_port'. By carefully timing and structuring the Discovery SVDM responses, an attacker can inject a chosen Standard or Vendor ID (SVID) from adjacent memory into the registration process, potentially bypassing intended hardware restrictions. Patches have been released across multiple stable kernel branches to enforce strict bounds checking on the SVID index.

Affected products

  • Linux Linux Kernel 4ab8c18d4d67 to 89ff289cbf5d3b659a2babc5ccaae4eaf7e7cf53

Timeline

  • 2026-06-22: other: Patch submitted by developer
  • 2026-07-24: patched: Commits merged into stable trees
  • 2026-07-25: disclosed: CVE published

References

Related threats