Bug 2492750 (CVE-2026-53196) - CVE-2026-53196 kernel: USB: serial: io_ti: fix heap overflow in get_manuf_info()
Summary: CVE-2026-53196 kernel: USB: serial: io_ti: fix heap overflow in get_manuf_info()
Keywords:
Status: NEW
Alias: CVE-2026-53196
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-06-25 10:03 UTC by OSIDB Bzimport
Modified: 2026-09-14 13:34 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:61887 0 None None None 2026-09-01 07:30:26 UTC
Red Hat Product Errata RHSA-2026:65708 0 None None None 2026-09-09 01:06:32 UTC
Red Hat Product Errata RHSA-2026:65709 0 None None None 2026-09-09 00:46:33 UTC
Red Hat Product Errata RHSA-2026:65710 0 None None None 2026-09-09 00:35:50 UTC
Red Hat Product Errata RHSA-2026:65711 0 None None None 2026-09-09 00:40:41 UTC
Red Hat Product Errata RHSA-2026:65712 0 None None None 2026-09-09 00:57:48 UTC
Red Hat Product Errata RHSA-2026:67114 0 None None None 2026-09-14 13:34:25 UTC

Description OSIDB Bzimport 2026-06-25 10:03:47 UTC
In the Linux kernel, the following vulnerability has been resolved:

USB: serial: io_ti: fix heap overflow in get_manuf_info()

get_manuf_info() reads le16_to_cpu(rom_desc->Size) bytes from the
device I2C EEPROM into a buffer allocated with kmalloc_obj(), which
is sizeof(struct edge_ti_manuf_descriptor) = 10 bytes.

The Size field comes from the device and is only validated (in
check_i2c_image()) to make sure the descriptor fits within
TI_MAX_I2C_SIZE (16384 bytes), not against the destination buffer size.
A malicious USB device can therefore set Size to any value up to 16377,
causing a heap overflow of up to 16367 bytes when plugged into a host
running this driver.

valid_csum() is called after read_rom() and also iterates
buffer[0..Size-1], compounding the out-of-bounds access.

Fix by rejecting descriptors with unexpected length before calling
read_rom().

[ johan: amend commit message; also check for short descriptors ]

Comment 4 errata-xmlrpc 2026-09-01 07:30:24 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:61887 https://access.redhat.com/errata/RHSA-2026:61887

Comment 5 errata-xmlrpc 2026-09-09 00:35:49 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2026:65710 https://access.redhat.com/errata/RHSA-2026:65710

Comment 6 errata-xmlrpc 2026-09-09 00:40:41 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On

Via RHSA-2026:65711 https://access.redhat.com/errata/RHSA-2026:65711

Comment 7 errata-xmlrpc 2026-09-09 00:46:32 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:65709 https://access.redhat.com/errata/RHSA-2026:65709

Comment 8 errata-xmlrpc 2026-09-09 00:57:47 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:65712 https://access.redhat.com/errata/RHSA-2026:65712

Comment 9 errata-xmlrpc 2026-09-09 01:06:31 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:65708 https://access.redhat.com/errata/RHSA-2026:65708

Comment 10 Jon Orris 2026-09-14 13:34:24 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:67114 https://access.redhat.com/errata/RHSA-2026:67114


Note You need to log in before you can comment on or make changes to this bug.