Executive brief
The Linux kernel's IMS Passenger Control Unit (PCU) input driver contains a flaw in how it parses USB CDC union descriptors. A malicious USB device could exploit this to cause the driver to enter an infinite loop, resulting in a system hang. This affects any system with an IMS PCU device connected.
Technical details
The vulnerability is a denial-of-service infinite loop in the ims_pcu_get_cdc_union_desc() function in drivers/input/misc/ims-pcu.c. The function iterates through CDC union descriptor data but fails to validate that the bLength field is at least 2 bytes; a malicious device providing bLength=0 causes the loop pointer to never advance, freezing indefinitely. The attack vector is adjacent (physical USB connection required) and requires no authentication. The fix adds a check ensuring bLength ≥ 2 before processing descriptors. A patch is available in the Linux kernel stable tree.
Affected products
- Linux Linux kernel multiple versions through 6.x (see kernel stable branches)
Timeline
- 2026-08-28: disclosed
- 2026-05-22: patched: Upstream patch committed by Dmitry Torokhov