Linux Kernel ISP1760 Driver Out-of-Bounds Array Access Vulnerability

Vulnerability

A vulnerability in the Linux kernel's ISP1760 USB driver has been identified, involving an out-of-bounds array access. This issue arises because the driver expects certain arrays to be a minimum length, but the arrays in question are dynamically sized during compilation. The vulnerability was detected using the Kernel Address Sanitizer, which reported a global out-of-bounds read by the 'swapper' task.

Impact

Exploitation of this vulnerability leads to a global out-of-bounds array access, which can potentially be exploited to overwrite memory and cause undefined behavior in the kernel.

Remediation

The vulnerability has been addressed by modifying the array definitions to prevent out-of-bounds access. Users should upgrade to the latest version of the Linux kernel where this fix has been applied.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
4.0
remediation
0.0
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.