Impact
The Linux kernel USBTMC driver assumes a two‑byte header without checking the URB’s actual_length. When the reported length is insufficient, the driver performs an out‑of‑bounds read of the data buffer or reuses leftover data from a previous notification. This flaw is classified as CWE‑125. An attacker capable of supplying malformed notifications could read kernel memory or cause a crash, compromising confidentiality and availability.
Affected Systems
All Linux kernel releases that contain the usbtmc driver and have not yet applied the recent patch are vulnerable. The advisory does not list specific kernel versions, so any system running a pre‑CVE‑2026‑63904 kernel should be considered at risk.
Risk and Exploitability
The.5 indicates moderate severity, while the EPSS score of less than 1% shows a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a USBTMC device capable of sending crafted interrupt‑ the attacker must have physical or administrative access to the device or the ability to control the USB subsystem. Given these constraints, the overall risk remains low to moderate; however, patching is advised to eliminate the potential for data leakage or system instability.
OpenCVE Enrichment
Ubuntu USN