Impact
The Linux kernel XHCI driver incorrectly assumes a Transfer Descriptor never spans more than two ring segments. When a TD covers three or more segments, only the last bounce buffer is recorded and later processed, while earlier bounce buffers are neither copied back into the user‑space buffer nor DMA unmapped. This logic bug results in stale or incorrect data remaining in destination buffers and causes a DMA mapping leak for each dropped bounce buffer. The bug can lead to data integrity failures and resource exhaustion without any obvious error indication.
Affected Systems
Linux kernel versions prior to commit 3c9a2b5a4f1183696f02ac280ced1d34afb409b1 are affected. The vulnerability occurs in the host's USB XHCI controller when handling bulk transfers. Administrators should verify that their systems are running a kernel that includes the patch or newer.
Risk and Exploitability
The EPSS score is listed as less than 1%, indicating a very low chance of exploitation, and the vulnerability is not catalogued in CISA KEV. Successful exploitation likely requires a locally attached malicious USB device, typically a mass storage device performing large, fragmented bulk transfers that cross multiple ring segments. The attacker can cause the kernel to report successful transfers while corrupting the data read by higher‑level services, potentially leading to data loss or integrity errors.
OpenCVE Enrichment
Debian DLA
Debian DSA