Linux Kernel mcba_usb Endpoint Type Validation Vulnerability

Vulnerability

A vulnerability in the Linux kernel's mcba_usb driver for CAN over USB interfaces has been addressed. The issue arose because the driver did not properly validate the endpoint type before submitting USB requests, leading to warnings about mismatched transfer pipes. This vulnerability could cause incorrect handling of USB data, potentially disrupting communication or data processing.

Impact

The vulnerability could lead to improper handling of USB requests, causing warnings about mismatched endpoint types and potentially disrupting normal data transfer operations.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
4.0
remediation
0.0
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.