CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's USB Test & Measurement Class (USBTMC) driver, which fails to validate the actual length of data received from interrupt notifications. This oversight can lead to out-of-bounds reads or the use of stale data, potentially compromising system stability or security. Organizations using Linux systems with USBTMC devices should prioritize this issue to mitigate risks associated with data integrity and system reliability.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: usb: usbtmc: check URB actual_length for interrupt-IN notifications USBTMC devices can use an optional interrupt endpoint for notification messages. These typically contain two-byte headers indicating the payload format, but the driver does not check if these headers are present before accessing the data buffers. In cases where the URB actual_length is not enough to fit these headers, the driver will either cause an out-of-bounds read, or consume stale leftover data from a previous notification. Fix by checking if actual_data contains enough bytes for the headers, otherwise resubmit URB to the interrupt endpoint.