Out-of-bounds read in Linux kernel - CVE-2026-64330
Published: July 27, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause incorrect registration of alternate modes.
The vulnerability exists due to an out-of-bounds read in svdm_consume_modes() when processing partner-supplied SVDM Discovery Modes data. A remote attacker can inject crafted SVDM values and drive the SVID index out of bounds to cause incorrect registration of alternate modes.
The issue can read adjacent fields in struct tcpm_port, and a connected USB Type-C partner can influence the loaded SVID value.
Affected software
Ubuntu
linux (Ubuntu package)
linux-azure (Ubuntu package)
linux-gcp-7.0 (Ubuntu package)
linux-oracle-7.0 (Ubuntu package)
linux-oem-7.0 (Ubuntu package)
linux-azure-7.0 (Ubuntu package)
How to mitigate CVE-2026-64330
linux (Ubuntu package) - addressed in versions 7.0.0-31.31, 7.0.0-31.31.1, 7.0.0-31.31~24.04.1, 7.0.0-1006.7, 7.0.0-1011.11~24.04.1, 7.0.0-1012.12, 7.0.0-1012.12~24.04.1
linux-azure (Ubuntu package) - addressed in versions 7.0.0-1011.11, 7.0.0-1014.14
linux-gcp-7.0 (Ubuntu package) - update to 7.0.0-1011.11~24.04.1
linux-oracle-7.0 (Ubuntu package) - update to 7.0.0-1011.11~24.04.1
linux-oem-7.0 (Ubuntu package) - update to 7.0.0-1013.13
linux-azure-7.0 (Ubuntu package) - update to 7.0.0-1014.14~24.04.1
External References
- https://git.kernel.org/stable/c/012406f89abc52d1d5f07aa5653b519ebf6d2407
- https://git.kernel.org/stable/c/313ca06e7e224ca1dfadd5722fe71fb8bc276b8b
- https://git.kernel.org/stable/c/3e1b1ac47e8163627f159f30d80d51b914620dd4
- https://git.kernel.org/stable/c/7b681dd5fbf60b24a13c14661e5b7735759fb491
- https://git.kernel.org/stable/c/89ff289cbf5d3b659a2babc5ccaae4eaf7e7cf53
- https://git.kernel.org/stable/c/c6d2af3b217a525741c472f0ab45d7d274b8468f
- https://git.kernel.org/stable/c/d638ec188e95fe60f4b01106ffd41958f8fb3c2c
- https://git.kernel.org/stable/c/f8163c414de8640f2ca82ce4dc93409d4cdc2fad