In the Linux kernel, the following vulnerability has been resolved:
usb: typec: tcpm: Validate SVID index in svdmconsumemodes()
In svdmconsumemodes(), the SVID value is read from pmdata->svids using pmdata->svid_index as an array index without bounds validation:
paltmode->svid = pmdata->svids[pmdata->svid_index];
If pmdata->svidindex is driven beyond SVIDDISCOVERYMAX (16), it results in an out-of-bounds read of the pmdata->svids array. Because pdmodedata is embedded inside struct tcpmport, indexing past svids reads into adjacent fields. In particular: - At index 16, it reads the altmodes count. - At index 18 and beyond, it reads into altmode_desc[], which contains partner-supplied SVDM Discovery Modes VDOs.
By injecting a chosen SVID into altmodedesc[0].vdo and driving svidindex to 20, the partner can force paltmode->svid to be loaded with an arbitrary, partner- chosen SVID, which is then registered via typecpartnerregister_altmode().
Fix this by validating that pmdata->svidindex is non-negative and strictly less than pmdata->nsvids before accessing the pmdata->svids array inside svdmconsume_modes().
{
"cna_assigner": "Linux",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64330.json"
}