Linux Kernel USB Type-C TCPM VDO Count Validation Vulnerability

Vulnerability

A vulnerability in the Linux kernel's USB Type-C TCPM (Type-C Port Management) driver has been addressed. The issue involved improper validation of the VDO (Vendor Defined Object) count received from a device during the Discover Identity ACK process. This lack of validation could allow a device-controlled value to index into static arrays, potentially leading to data leakage.

Impact

The vulnerability could result in unintended data exposure due to improper validation of device-controlled values, allowing for potential data leakage from the kernel.

Reproduction

The vulnerability can be reproduced by connecting a USB Type-C device that sends an invalid VDO count during the Discover Identity process. The TCPM driver will then improperly handle the VDO data, leading to a potential leak of sensitive information.

Remediation

Users can upgrade to the latest version of the Linux kernel where this vulnerability has been fixed. Instructions for downloading the patched kernel can be found on the official Linux kernel website.

Added: Jul 19, 2026, 7:33 PM
Updated: Jul 19, 2026, 7:33 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
0.6
exploitability
2.9
remediation
7.7
relevance
9.7
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.