Description
In the Linux kernel, the following vulnerability has been resolved:

usb: image: mdc800: change kmalloc() to kzalloc()

Change the kmalloc() calls in usb_mdc800_init() for irq_urb_buffer and
download_urb_buffer to kzalloc(), avoiding potential stack leaks if a
shorter message is received in mdc800_usb_irq() and
mdc800_usb_download_notify()
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure from Stack Leak
Action: Apply Patch
AI Analysis

Impact

The vulnerability was a kernel bug in the USB image driver for the MDC800 device. The driver allocated buffers with kmalloc() that were not zero‑initialized. When a shorter USB message arrived, leftover bytes from the previous allocation could remain in the buffer, leaking kernel stack contents. This could provide an attacker with sensitive internal data, leading to information disclosure.

Affected Systems

Any Linux system using the default kernel with the usb_mdc800 driver before the patch is affected. All distributions that ship the kernel version containing the bug – according to the CPE, linux_kernel.* – are potentially impacted until they apply the fix.

Risk and Exploitability

The EPSS score is below 1%, and the vulnerability is not listed in the CISA KEV catalog, indicating a low but not negligible chance of exploitation. The attack requires local or physical access to the USB MDC800 device and the ability to inject crafted messages; it does not provide remote code execution or privilege escalation. The patch that changes kmalloc() to kzalloc() eliminates the leak entirely.

Generated by OpenCVE AI on September 18, 2026 at 04:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update your Linux kernel to a version that includes the USB MDC800 driver patch.
  • If an upgrade is not possible, disable the usb_mdc800 driver or remove the device to prevent any interaction.
  • Limit who can load or interact with the usb_mdc800 driver, for example by applying kernel module parameter restrictions.
  • Monitor kernel logs for anomalous USB activity and consider enforcing SELinux or AppArmor policies to constrain USB drivers.

Generated by OpenCVE AI on September 18, 2026 at 04:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: usb: image: mdc800: change kmalloc() to kzalloc() Change the kmalloc() calls in usb_mdc800_init() for irq_urb_buffer and download_urb_buffer to kzalloc(), avoiding potential stack leaks if a shorter message is received in mdc800_usb_irq() and mdc800_usb_download_notify()
Title usb: image: mdc800: change kmalloc() to kzalloc()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T09:29:28.837Z

Reserved: 2026-09-11T19:38:34.782Z

Link: CVE-2026-90034

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:16.567

Modified: 2026-09-17T10:17:06.167

Link: CVE-2026-90034

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T19:30:12Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor