Linux Kernel USB Serial MXUport Endpoint Size Vulnerability Memory Corruption

Vulnerability

A memory corruption vulnerability has been addressed in the Linux kernel's USB serial MXUport driver. The issue arose because the driver did not properly validate the maximum packet size of bulk-out endpoints, allowing user-controlled slab corruption. This could occur if a malicious device reported a smaller endpoint size, leading to memory corruption. The vulnerability affects several versions of the Linux kernel.

Impact

The vulnerability could be exploited to cause memory corruption, potentially leading to arbitrary code execution or other malicious actions.

Reproduction

The vulnerability can be reproduced by connecting a malicious USB device that reports a bulk-out endpoint maximum packet size of less than eight bytes. This will trigger the memory corruption issue in the MXUport driver.

Remediation

Users can update to the latest version of the Linux kernel where this vulnerability has been fixed. Instructions for updating the kernel can be found in the official Linux kernel documentation.

Added: Jul 19, 2026, 8:22 PM
Updated: Jul 19, 2026, 8:22 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
0.6
exploitability
2.9
remediation
7.7
relevance
9.7
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.