Impact
The vulnerability resides in the Linux kernel USB serial driver for mxuport hardware. A malicious USB device that reports a bulk‑out endpoint with a maximum packet size smaller than eight bytes can cause the driver to copy data into a slab allocation without proper bounds checking. This results in kernel‑level memory corruption that can destabilize the system, potentially leading to crashes or other disruptive behavior.
Affected Systems
The affected product is the Linux kernel, as identified by the kernel CPE entry. No specific kernel versions or release dates are listed in the data, so all kernels containing an unpatched mxuport driver are potentially impacted.
Risk and Exploitability
The CVSS score of 7.0 indicates medium‑to‑high severity. The EPSS score of less than 1 % indicates a very low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector would be local, requiring a malicious USB device to be physically connected to the system. The risk is therefore limited to environments where untrusted USB hardware can be introduced.
OpenCVE Enrichment
Ubuntu USN