Impact
A missing bounds check in the USB serial option driver causes an out‑of‑bounds read when an interrupt IN endpoint reports a packet smaller than its declared maximum length. The driver reads past the allocated buffer, potentially exposing data from the kernel address space.
Affected Systems
All Linux kernel releases that lack the commit 030e3a73d3c3aa67c44454649e984d6383cdb7d3 or later. The vendor is Linux, product Linux kernel, with any version before the patch applied.
Risk and Exploitability
The CVSS score is not provided and EPSS is not available, so the quantitative risk is unclear. The bug requires a USB device that presents a short interrupt packet; an attacker must have local physical access to plug such a device into the target. While the flaw does not grant code execution, it can leak kernel memory contents or trigger a crash, potentially resulting in information disclosure or denial of service.
OpenCVE Enrichment