SB2026072836 - Out-of-bounds read in Linux kernel net usb driver
Published: July 28, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2026-64540)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows an attacker with physical access to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in genelink_rx_fixup() when processing device-supplied aggregated RX frames from a crafted GeneLink (GL620A) USB device. An attacker with physical access can provide a short URB with inconsistent packet length metadata to disclose sensitive information.
The issue can leak adjacent kernel heap contents to the network stack as soon as the USB network interface is up.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0575599e451aff3c5329922562374a2cab25fc51
- https://git.kernel.org/stable/c/0a7d9c7c5f1f208c523abbb4db6aea7bc1fad3db
- https://git.kernel.org/stable/c/255d03551f94c7bdd86c7d9181a70b21917d829f
- https://git.kernel.org/stable/c/3ef79fa3860e644c8de7834fa7300e1c58f38862
- https://git.kernel.org/stable/c/4359376e6238d89977a35086e47ca3b07f43e850
- https://git.kernel.org/stable/c/573418f7ea8f859a841417eb4b915594094fd967
- https://git.kernel.org/stable/c/8624e179fa3ce23c2fbd1a198ce30764b73f054a
- https://git.kernel.org/stable/c/8ff7f2a6da4fccaa5cc9be7251a24e71e29fbd1a