Executive brief
A vulnerability in the Linux kernel's driver for GeneLink (GL620A) USB networking cables could allow a malicious USB device to leak sensitive information from the computer's memory. By sending specially crafted data packets that claim to be larger than they actually are, the device can force the system to read and transmit adjacent data from the kernel's internal memory. This could result in the exposure of private system information to an attacker with physical access to a USB port.
Technical details
An out-of-bounds read exists in the genelink_rx_fixup() function within drivers/net/usb/gl620a.c. The driver processes aggregated RX frames by trusting a device-supplied per-packet length field without verifying it against the actual size of the received URB. A malicious GeneLink device can provide a length value up to 1514 bytes that exceeds the actual buffer size, causing skb_put_data() to copy adjacent slab memory into a new socket buffer that is then passed up the network stack. The fix involves validating the packet length using skb_pull() before performing the data copy.
Affected products
- Linux Linux Kernel 47ee3051c856 to 8ff7f2a6da4f
Timeline
- 2026-06-27: disclosed: Initial patch submission by Xiang Mei
- 2026-07-24: patched: Patch committed to stable trees
- 2026-07-27: advisory: CVE published in NVD dataset
References
- https://git.kernel.org/stable/c/0575599e451aff3c5329922562374a2cab25fc51
- https://git.kernel.org/stable/c/0a7d9c7c5f1f208c523abbb4db6aea7bc1fad3db
- https://git.kernel.org/stable/c/255d03551f94c7bdd86c7d9181a70b21917d829f
- https://git.kernel.org/stable/c/3ef79fa3860e644c8de7834fa7300e1c58f38862
- https://git.kernel.org/stable/c/4359376e6238d89977a35086e47ca3b07f43e850
- https://git.kernel.org/stable/c/573418f7ea8f859a841417eb4b915594094fd967
- https://git.kernel.org/stable/c/8624e179fa3ce23c2fbd1a198ce30764b73f054a