Linux Kernel Digi Acceleport USB Driver Memory Corruption Vulnerability

Vulnerability

A memory corruption vulnerability has been identified in the Linux kernel's USB serial Digi Acceleport driver. This issue arises from the absence of proper sanity checks on the bulk-out buffer sizes, allowing for out-of-bounds memory accesses or slab corruption. The vulnerability can be exploited if a malicious device reports smaller buffer sizes than expected. The problem has been addressed by adding the necessary buffer size checks to prevent such memory corruption.

Impact

Exploitation of this vulnerability could lead to memory corruption, allowing for potential arbitrary code execution or causing a denial-of-service condition by crashing the system.

Reproduction

The vulnerability can be reproduced by connecting a malicious USB device to a system running an affected version of the Linux kernel. The device must be able to communicate with the Digi Acceleport driver and report smaller buffer sizes than expected. This will trigger the missing sanity checks, leading to out-of-bounds memory accesses or slab corruption.

Remediation

Users can upgrade to the latest version of the Linux kernel where this vulnerability has been fixed. Instructions for downloading the patched kernel can be found on the official Linux kernel website.

Added: Jul 19, 2026, 8:20 PM
Updated: Jul 19, 2026, 8:20 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
0.6
exploitability
2.9
remediation
7.7
relevance
9.7
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.