Information disclosure in Linux kernel - CVE-2026-64336

 

Information disclosure in Linux kernel - CVE-2026-64336

Published: July 27, 2026


Vulnerability identifier: #VU139642
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2026-64336
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available
Vendor: Linux Foundation
Affected software:
Linux kernel

Detailed vulnerability description

The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to an information leak in the keyspan_pda USB serial driver write() callback when handling write operations. A local user can trigger a write operation that causes the line discipline to continue reading data beyond the tty write buffer to disclose sensitive information.

The issue occurs because the driver may report accepting more characters than were actually passed to write().


How to mitigate CVE-2026-64336

Install security update from vendor's repository.

Sources