Description
In the Linux kernel, the following vulnerability has been resolved:

HID: mcp2221: clear rxbuf after I2C/SMBus transfer completes

mcp_i2c_smbus_read() stores the caller-supplied buffer pointer in
mcp->rxbuf for the duration of a transfer but never clears it when the
transfer finishes or times out. Once the caller frees or reuses the
buffer, mcp->rxbuf becomes a dangling pointer. A delayed or spurious
MCP2221_I2C_GET_DATA report can then drive mcp2221_raw_event() to
memcpy device data into the freed memory, causing a write
use-after-free.

Route all return paths through a single exit point that clears
mcp->rxbuf and mcp->rxbuf_size, so that the existing !mcp->rxbuf guard
in the raw_event handler can reject any report arriving after the
transfer has ended.
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption that may destabilize the system
Action: Apply Patch
AI Analysis

Impact

A write use‑after‑free occurs in the Linux kernel’s HID:mcp2221 driver when an I2C/SMBus read operation stores the caller‑supplied buffer pointer in the device structure but never clears it after the transfer finishes or times out. When the caller later frees or reuses that buffer, the driver’s raw event handler later writes incoming data into the freed memory, corrupting kernel memory and potentially crashing or destabilizing the system. This flaw is a classic use‑after‑free, classified as CWE‑825.

Affected Systems

This flaw appears in all Linux kernels that include the mcp2221 HID driver before the patch that clears rxbuf. Every distribution or vendor that loads this driver on an unpatched kernel is vulnerable, meaning any Linux system with the MCP2221 USB driver enabled is affected.

Risk and Exploitability

Based on the description, the likely attack vector is local, requiring the attacker to have a connected MCP2221 device and the ability to initiate an I2C/SMBus read that triggers a delayed or spurious MCP2221_I2C_GET_DATA report. The CVSS score of 7.8 indicates moderate severity, while the EPSS score of < 1% signals a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation would result in kernel memory corruption through a write use‑after‑free, which could lead to a system crash or privilege escalation.

Generated by OpenCVE AI on September 15, 2026 at 21:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that contains the mcp2221 driver fix that clears the rxbuf pointer after transfer completion or timeout.
  • If an immediate kernel upgrade is not possible, disable or blacklist the mcp2221 HID driver so that it does not load during boot or runtime.
  • Limit access to the MCP2221 device by removing it from the system or applying USB device restrictions that prevent the driver from interacting with the device.

Generated by OpenCVE AI on September 15, 2026 at 21:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 21 Sep 2026 13:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.0, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.0, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

threat_severity

Important


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: HID: mcp2221: clear rxbuf after I2C/SMBus transfer completes mcp_i2c_smbus_read() stores the caller-supplied buffer pointer in mcp->rxbuf for the duration of a transfer but never clears it when the transfer finishes or times out. Once the caller frees or reuses the buffer, mcp->rxbuf becomes a dangling pointer. A delayed or spurious MCP2221_I2C_GET_DATA report can then drive mcp2221_raw_event() to memcpy device data into the freed memory, causing a write use-after-free. Route all return paths through a single exit point that clears mcp->rxbuf and mcp->rxbuf_size, so that the existing !mcp->rxbuf guard in the raw_event handler can reject any report arriving after the transfer has ended.
Title HID: mcp2221: clear rxbuf after I2C/SMBus transfer completes
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-21T13:14:34.683Z

Reserved: 2026-09-11T19:38:34.737Z

Link: CVE-2026-89622

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:47.517

Modified: 2026-09-21T14:17:23.960

Link: CVE-2026-89622

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T19:45:20Z

Links: CVE-2026-89622 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T21:15:14Z

Weaknesses
  • CWE-825

    Expired Pointer Dereference