Linux Kernel Keyspan USB Serial Driver Missing Sanity Check Vulnerability

Vulnerability

A vulnerability exists in the Linux kernel's USB serial Keyspan driver, specifically for the USA-49WG model. The issue arises from a missing sanity check on incoming data transfers, which can lead to the driver parsing outdated or uninitialized memory. This vulnerability has been addressed by adding the necessary checks to prevent such data from being processed.

Impact

The absence of proper data validation could allow for the manipulation of memory, potentially leading to undefined behavior in the driver.

Reproduction

The vulnerability can be reproduced by connecting a Keyspan USA-49WG USB serial device to a system running an affected version of the Linux kernel. Once the device is connected, the driver will handle incoming data transfers without the necessary sanity checks, allowing for the parsing of stale or uninitialized slab data.

Remediation

Users can upgrade to the latest version of the Linux kernel where this vulnerability has been fixed. Instructions for downloading the patched kernel can be found on the official Linux kernel website.

Added: Jul 19, 2026, 8:20 PM
Updated: Jul 19, 2026, 8:20 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
0.6
exploitability
4.3
remediation
7.7
relevance
9.7
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.