Executive brief
A vulnerability in the Linux kernel's Intel USBIO bridge driver could allow a malicious USB device to access sensitive information from the computer's memory. By mimicking a legitimate USB device but providing inconsistent data size information, the device can trick the system into reading more data than intended. This could lead to the exposure of private data from other applications or system processes to a local user.
Technical details
A slab-out-of-bounds read exists in drivers/usb/misc/usbio.c within the usbio_bulk_msg() function. The vulnerability occurs because the driver fails to validate the device-supplied packet length (bpkt_len) against the actual received transfer length (act) or the receive buffer size (rxbuf_len). Instead, it incorrectly validates it against the transmit buffer size (txbuf_len). A malicious USB device can advertise mismatched endpoint sizes to trigger a memcpy() that reads past the end of the rxbuf slab object. This over-read data is then passed back to the i2c layer and potentially to userspace via i2c-dev, leading to information disclosure. The issue has been patched by adding a check to ensure bpkt_len does not exceed the actual received payload size.
Affected products
- Linux Linux Kernel 121a0f839dbb to 48394f94211cf, 8c6314489550f, fc1b546973c14
Timeline
- 2026-06-24: other: Vulnerability fixed in kernel source
- 2026-07-25: disclosed: CVE published