Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
- >= 2.6.26, < 2.6.26.1
A memory corruption vulnerability has been identified in the Linux kernel's USB serial Cypress M8 driver. This issue arises because the driver does not properly validate the maximum packet size of interrupt-out endpoints. If a malicious device reports a size smaller than eight bytes, it can lead to user-controlled memory corruption or a NULL-pointer dereference.
Exploitation of this vulnerability can cause memory corruption, allowing for potential arbitrary code execution or causing a system crash.
The vulnerability can be reproduced by connecting a malicious USB device that reports an interrupt-out endpoint packet size of less than eight bytes. This will trigger the Cypress M8 USB driver to improperly handle the endpoint size, leading to memory corruption.
Users can update to the latest version of the Linux kernel where this vulnerability has been fixed. Instructions for updating the kernel can be found in the official Linux kernel documentation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.