Out-of-bounds read in Linux kernel - CVE-2026-64330

 

Out-of-bounds read in Linux kernel - CVE-2026-64330

Published: July 27, 2026


Vulnerability identifier: #VU139652
CSH Severity: Low
CVSS v4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-64330
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause incorrect registration of alternate modes.

The vulnerability exists due to an out-of-bounds read in svdm_consume_modes() when processing partner-supplied SVDM Discovery Modes data. A remote attacker can inject crafted SVDM values and drive the SVID index out of bounds to cause incorrect registration of alternate modes.

The issue can read adjacent fields in struct tcpm_port, and a connected USB Type-C partner can influence the loaded SVID value.


Affected software

Linux kernel

How to mitigate CVE-2026-64330

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins