usb: typec: tcpm: Validate SVID index in svdm_consume_modes()

Summary

CVECVE-2026-64330
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-07-25 10:17:14 UTC
Updated2026-07-25 10:17:14 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: usb: typec: tcpm: Validate SVID index in svdm_consume_modes() In svdm_consume_modes(), the SVID value is read from pmdata->svids using pmdata->svid_index as an array index without bounds validation: paltmode->svid = pmdata->svids[pmdata->svid_index]; If pmdata->svid_index is driven beyond SVID_DISCOVERY_MAX (16), it results in an out-of-bounds read of the pmdata->svids array. Because pd_mode_data is embedded inside struct tcpm_port, indexing past svids reads into adjacent fields. In particular: - At index 16, it reads the altmodes count. - At index 18 and beyond, it reads into altmode_desc[], which contains partner-supplied SVDM Discovery Modes VDOs. By injecting a chosen SVID into altmode_desc[0].vdo and driving svid_index to 20, the partner can force paltmode->svid to be loaded with an arbitrary, partner- chosen SVID, which is then registered via typec_partner_register_altmode(). Fix this by validating that pmdata->svid_index is non-negative and strictly less than pmdata->nsvids before accessing the pmdata->svids array inside svdm_consume_modes().

Risk And Classification

EPSS: 0.001770000 probability, percentile 0.075010000 (date 2026-07-28)

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 4ab8c18d4d67321cc7b660559de17511d4fc0237 89ff289cbf5d3b659a2babc5ccaae4eaf7e7cf53 git Not specified
CNA Linux Linux affected 4ab8c18d4d67321cc7b660559de17511d4fc0237 d638ec188e95fe60f4b01106ffd41958f8fb3c2c git Not specified
CNA Linux Linux affected 4ab8c18d4d67321cc7b660559de17511d4fc0237 f8163c414de8640f2ca82ce4dc93409d4cdc2fad git Not specified
CNA Linux Linux affected 4ab8c18d4d67321cc7b660559de17511d4fc0237 012406f89abc52d1d5f07aa5653b519ebf6d2407 git Not specified
CNA Linux Linux affected 4ab8c18d4d67321cc7b660559de17511d4fc0237 c6d2af3b217a525741c472f0ab45d7d274b8468f git Not specified
CNA Linux Linux affected 4ab8c18d4d67321cc7b660559de17511d4fc0237 3e1b1ac47e8163627f159f30d80d51b914620dd4 git Not specified
CNA Linux Linux affected 4ab8c18d4d67321cc7b660559de17511d4fc0237 313ca06e7e224ca1dfadd5722fe71fb8bc276b8b git Not specified
CNA Linux Linux affected 4ab8c18d4d67321cc7b660559de17511d4fc0237 7b681dd5fbf60b24a13c14661e5b7735759fb491 git Not specified
CNA Linux Linux affected 4.19 Not specified
CNA Linux Linux unaffected 4.19 semver Not specified
CNA Linux Linux unaffected 5.10.261 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.212 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.178 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.145 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.96 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.39 6.18.* semver Not specified
CNA Linux Linux unaffected 7.1.4 7.1.* semver Not specified
CNA Linux Linux unaffected 7.2-rc3 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/3e1b1ac47e8163627f159f30d80d51b914620dd4 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/89ff289cbf5d3b659a2babc5ccaae4eaf7e7cf53 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/7b681dd5fbf60b24a13c14661e5b7735759fb491 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/313ca06e7e224ca1dfadd5722fe71fb8bc276b8b 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/012406f89abc52d1d5f07aa5653b519ebf6d2407 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/c6d2af3b217a525741c472f0ab45d7d274b8468f 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/d638ec188e95fe60f4b01106ffd41958f8fb3c2c 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/f8163c414de8640f2ca82ce4dc93409d4cdc2fad 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report