Junglewise Threat Intelligence

CVE-2026-80594: Linux kernel ims-pcu infinite loop in CDC union descriptor parsing

CVE-2026-80594 · Severity: info · Published 2026-08-28

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's IMS Passenger Control Unit (PCU) input driver contains a flaw in how it parses USB CDC union descriptors. A malicious USB device could exploit this to cause the driver to enter an infinite loop, resulting in a system hang. This affects any system with an IMS PCU device connected.

Technical details

The vulnerability is a denial-of-service infinite loop in the ims_pcu_get_cdc_union_desc() function in drivers/input/misc/ims-pcu.c. The function iterates through CDC union descriptor data but fails to validate that the bLength field is at least 2 bytes; a malicious device providing bLength=0 causes the loop pointer to never advance, freezing indefinitely. The attack vector is adjacent (physical USB connection required) and requires no authentication. The fix adds a check ensuring bLength ≥ 2 before processing descriptors. A patch is available in the Linux kernel stable tree.

Affected products

  • Linux Linux kernel multiple versions through 6.x (see kernel stable branches)

Timeline

  • 2026-08-28: disclosed
  • 2026-05-22: patched: Upstream patch committed by Dmitry Torokhov

References

Related threats