SB20260727250 - Out-of-bounds read in Linux kernel typec tcpm driver



SB20260727250 - Out-of-bounds read in Linux kernel typec tcpm driver

Published: July 27, 2026

Security Bulletin ID SB20260727250
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Physical access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Out-of-bounds read (CVE-ID: CVE-2026-64330)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause incorrect registration of alternate modes.

The vulnerability exists due to an out-of-bounds read in svdm_consume_modes() when processing partner-supplied SVDM Discovery Modes data. A remote attacker can inject crafted SVDM values and drive the SVID index out of bounds to cause incorrect registration of alternate modes.

The issue can read adjacent fields in struct tcpm_port, and a connected USB Type-C partner can influence the loaded SVID value.


Remediation

Install update from vendor's website.