Impact
The Linux kernel’s omninet USB serial driver reported by a connected USB device. When a malicious device reports a smaller endpoint max packet size than the hardcoded transfer size, the driver’s bulk‑out buffer is smaller than the data transferred, leading to a user‑controlled slab corruption. This corruption can compromise kernel memory integrity, potentially allowing an attacker to gain elevated privileges or cause a denial‑of‑service by crashing the kernel.
Affected Systems
All Linux kernel versions that include the omninet USB serial driver without the patch. The affected component is the Linux kernel’s omninet driver and any system running a kernel that lacks the recent commit correcting the buffer size check.
Risk and Exploitability
The CVSS score of 7.0 classifies the problem as high severity, but the EPSS score of less than 1% shows that real‑world exploitation is rare. The vulnerability would require a physical or local attacker to present a specially crafted USB device to the target, so it is a local attack vector. It is not listed in the CISA KEV catalog, further indicating that no publicly known exploits exist at this time.
OpenCVE Enrichment
Ubuntu USN