Information disclosure in Linux kernel - CVE-2026-64336

 

Information disclosure in Linux kernel - CVE-2026-64336

Published: July 27, 2026


Vulnerability identifier: #VU139642
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-64336
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to an information leak in the keyspan_pda USB serial driver write() callback when handling write operations. A local user can trigger a write operation that causes the line discipline to continue reading data beyond the tty write buffer to disclose sensitive information.

The issue occurs because the driver may report accepting more characters than were actually passed to write().


Affected software

Linux kernel
Ubuntu
linux (Ubuntu package)
linux-gcp-7.0 (Ubuntu package)
linux-oem-7.0 (Ubuntu package)

How to mitigate CVE-2026-64336

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
linux (Ubuntu package) - addressed in versions 7.0.0-31.31, 7.0.0-31.31.1, 7.0.0-31.31~24.04.1, 7.0.0-1006.7, 7.0.0-1011.11~24.04.1, 7.0.0-1012.12, 7.0.0-1012.12~24.04.1
linux-gcp-7.0 (Ubuntu package) - update to 7.0.0-1011.11~24.04.1
linux-oem-7.0 (Ubuntu package) - update to 7.0.0-1013.13

External References

Related Security Bulletins