Executive brief
The MCP2221 is a USB-to-I2C/SMBus bridge chip driver used in hardware interfaces and embedded systems. A use-after-free vulnerability allows an attacker with local access to send malicious USB HID reports that write data into memory that has already been freed, potentially leading to kernel crashes, information disclosure, or code execution.
Technical details
The vulnerability is a use-after-free bug in the mcp2221 HID driver (drivers/hid/hid-mcp2221.c). The mcp_i2c_smbus_read() function stores a caller-supplied buffer pointer in mcp->rxbuf but never clears it when the transfer completes or times out. After the caller frees the buffer, mcp->rxbuf becomes a dangling pointer. A delayed or spurious MCP2221_I2C_GET_DATA HID report can then trigger mcp2221_raw_event() to memcpy device data into the freed memory. The fix routes all return paths through a single exit point that clears both mcp->rxbuf and mcp->rxbuf_size, allowing the existing null-check guard in raw_event to reject reports after transfer completion. Attack requires local access to the USB device or ability to send HID reports.
Affected products
- Linux Linux kernel versions with MCP2221 HID driver support (affected in multiple kernel series from 4.x through 7.x based on backport availability)
Timeline
- 2026-09-07: other: Patch authored by Jiangshan Yi
- 2026-09-11: patched: Fix merged and released in mainline kernel and stable branches