SB20260727238 - Improper control of a resource through its lifetime in Linux kernel usb serial driver
Published: July 27, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-64335)
CWE-ID: CWE-664 - Improper control of a resource through its lifetime
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper state management in the digi_acceleport usb serial driver when reopening a port after it was closed while throttled. A local user can close and reopen a throttled port to cause a denial of service.
The issue prevents the port from receiving further data until the device is reconnected or the driver is rebound.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/4f3f6f44db71e469933a7c36c5d57d937ba0a21b
- https://git.kernel.org/stable/c/61954033326fc7e637ed2aeeb4b52021e0ee4657
- https://git.kernel.org/stable/c/83a3dfc018943b05b6daf3a6f891833e1aabfa1f
- https://git.kernel.org/stable/c/8d50a910194f66566a5eb252b33283855c8d5203
- https://git.kernel.org/stable/c/92fa3e1a49848509ea3f7995751963fc65095998
- https://git.kernel.org/stable/c/abacd67e6f689c62d8a13e3da25f4272bc9ad4af
- https://git.kernel.org/stable/c/d5d2660caef78d4c996d34d123574c8e86f5b5ac
- https://git.kernel.org/stable/c/eab394781e9321c0c7e97a24fd092387cb262f40