CVE-2026-64330 Details
Description
In the Linux kernel, the following vulnerability has been resolved: usb: typec: tcpm: Validate SVID index in svdm_consume_modes() In svdm_consume_modes(), the SVID value is read from pmdata->svids using pmdata->svid_index as an array index without bounds validation: paltmode->svid = pmdata->svids[pmdata->svid_index]; If pmdata->svid_index is driven beyond SVID_DISCOVERY_MAX (16), it results in an out-of-bounds read of the pmdata->svids array. Because pd_mode_data is embedded inside struct tcpm_port, indexing past svids reads into adjacent fields. In particular: - At index 16, it reads the altmodes count. - At index 18 and beyond, it reads into altmode_desc[], which contains partner-supplied SVDM Discovery Modes VDOs. By injecting a chosen SVID into altmode_desc[0].vdo and driving svid_index to 20, the partner can force paltmode->svid to be loaded with an arbitrary, partner- chosen SVID, which is then registered via typec_partner_register_altmode(). Fix this by validating that pmdata->svid_index is non-negative and strictly less than pmdata->nsvids before accessing the pmdata->svids array inside svdm_consume_modes().
A vulnerability in the Linux kernel's USB Type-C TCPM (Type-C Port Management) implementation allows for out-of-bounds reads of the SVID (Standard Vendor ID) array. This issue arises in the 'svdm_consume_modes()' function, where the SVID index is not properly validated before being used to access the SVIDs array. If the index exceeds the maximum allowed value, it can read into adjacent memory fields, potentially leading to arbitrary data manipulation. The vulnerability can be exploited by injecting a chosen SVID into a specific memory location and driving the index to a value that triggers the out-of-bounds read.
The vulnerability has been addressed by adding validation to ensure that the SVID index is non-negative and strictly less than the number of SVIDs before accessing the SVIDs array. Users should update to the latest version of the Linux kernel where this fix has been applied.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/012406f89abc52d1d5f07aa5653b519ebf6d2407 | kernel.org | Patch |
| https://git.kernel.org/stable/c/313ca06e7e224ca1dfadd5722fe71fb8bc276b8b | kernel.org | Patch |
| https://git.kernel.org/stable/c/3e1b1ac47e8163627f159f30d80d51b914620dd4 | kernel.org | Patch |
| https://git.kernel.org/stable/c/7b681dd5fbf60b24a13c14661e5b7735759fb491 | kernel.org | Patch |
| https://git.kernel.org/stable/c/89ff289cbf5d3b659a2babc5ccaae4eaf7e7cf53 | kernel.org | Patch |
| https://git.kernel.org/stable/c/c6d2af3b217a525741c472f0ab45d7d274b8468f | kernel.org | Patch |
| https://git.kernel.org/stable/c/d638ec188e95fe60f4b01106ffd41958f8fb3c2c | kernel.org | Patch |
| https://git.kernel.org/stable/c/f8163c414de8640f2ca82ce4dc93409d4cdc2fad | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-129 | Improper Validation of Array Index | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 4.19, < 5.10.261 >= 5.11, < 5.15.212 >= 5.16, < 6.1.178 >= 6.2, < 6.6.145 >= 6.7, < 6.12.96 >= 6.13, < 6.18.39 >= 6.19, < 7.1.4 7.2 rc1 7.2 rc2 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 4, 2026 | Initial Analysis | [email protected] |
| Aug 17, 2026 | CVE Modified | kernel.org |
| Jul 25, 2026 | New CVE Received | kernel.org |