Linux Kernel Cypress M8 USB Driver Memory Corruption Vulnerability

Vulnerability

A memory corruption vulnerability has been identified in the Linux kernel's USB serial Cypress M8 driver. This issue arises because the driver does not properly validate the maximum packet size of interrupt-out endpoints. If a malicious device reports a size smaller than eight bytes, it can lead to user-controlled memory corruption or a NULL-pointer dereference.

Impact

Exploitation of this vulnerability can cause memory corruption, allowing for potential arbitrary code execution or causing a system crash.

Reproduction

The vulnerability can be reproduced by connecting a malicious USB device that reports an interrupt-out endpoint packet size of less than eight bytes. This will trigger the Cypress M8 USB driver to improperly handle the endpoint size, leading to memory corruption.

Remediation

Users can update to the latest version of the Linux kernel where this vulnerability has been fixed. Instructions for updating the kernel can be found in the official Linux kernel documentation.

Added: Jul 19, 2026, 7:38 PM
Updated: Jul 19, 2026, 7:38 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
3.1
exploitability
2.9
remediation
7.7
relevance
9.7
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.