Linux Kernel USB Type-C DisplayPort Status Update VDO Count Validation Vulnerability

Vulnerability

A vulnerability in the Linux kernel's USB Type-C DisplayPort altmode handling has been addressed. A broken or malicious device can send an incorrect count for a status update VDO, leading the kernel to read uninitialized stack data and potentially expose it elsewhere. The vulnerability arises from insufficient validation of the count before processing the VDO update. This issue affects the stable versions of the Linux kernel.

Impact

The vulnerability could be exploited to read uninitialized stack data, which could then be manipulated or sent elsewhere, potentially leading to arbitrary code execution or other malicious outcomes.

Reproduction

The vulnerability can be reproduced by connecting a device that sends an incorrect count for a status update VDO. This will cause the Linux kernel to read uninitialized stack data and send it off, exploiting the lack of proper count validation.

Remediation

Users can upgrade to the latest stable version of the Linux kernel, where this vulnerability has been fixed. Instructions for downloading the updated kernel can be found on the official Linux kernel website.

Added: Jul 19, 2026, 7:35 PM
Updated: Jul 19, 2026, 7:35 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
0.6
exploitability
4.3
remediation
7.7
relevance
9.7
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.