Executive brief
The IMS Passenger Control Unit (ims-pcu) input driver in the Linux kernel failed to validate the length of device responses before accessing response buffers. A malicious or faulty USB device could send incomplete responses, causing the driver to read beyond allocated buffer boundaries and potentially crash the system or access sensitive kernel memory.
Technical details
The ims-pcu driver processes USB device responses by reading data from fixed-size buffers without first checking that the device sent the expected number of bytes. This is a classic out-of-bounds read vulnerability affecting multiple code paths: button event reporting, bootloader commands, firmware info retrieval, LED brightness control, and optical navigation configuration. The fix adds length validation checks before each buffer access, comparing the actual response length against the minimum expected size and returning an error if the response is truncated. The vulnerability requires a malicious or corrupted USB device to trigger—no user interaction or network access is needed beyond physical USB connection.
Affected products
- Linux Linux kernel Linux 2.6.11 through 7.2 and master branches (ims-pcu driver)
Timeline
- 2026-05-22: disclosed: Patch authored by Dmitry Torokhov
- 2026-06-06: patched: Patch committed upstream
- 2026-07-24: patched: Patch backported to stable kernels
- 2026-08-28: advisory: CVE-2026-80595 published