CVE-2026-64330

Source
https://cve.org/CVERecord?id=CVE-2026-64330
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64330.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-64330
Downstream
Published
2026-07-25T08:49:57.734Z
Modified
2026-07-27T04:03:19.894874443Z
Summary
usb: typec: tcpm: Validate SVID index in svdm_consume_modes()
Details

In the Linux kernel, the following vulnerability has been resolved:

usb: typec: tcpm: Validate SVID index in svdmconsumemodes()

In svdmconsumemodes(), the SVID value is read from pmdata->svids using pmdata->svid_index as an array index without bounds validation:

paltmode->svid = pmdata->svids[pmdata->svid_index];

If pmdata->svidindex is driven beyond SVIDDISCOVERYMAX (16), it results in an out-of-bounds read of the pmdata->svids array. Because pdmodedata is embedded inside struct tcpmport, indexing past svids reads into adjacent fields. In particular: - At index 16, it reads the altmodes count. - At index 18 and beyond, it reads into altmode_desc[], which contains partner-supplied SVDM Discovery Modes VDOs.

By injecting a chosen SVID into altmodedesc[0].vdo and driving svidindex to 20, the partner can force paltmode->svid to be loaded with an arbitrary, partner- chosen SVID, which is then registered via typecpartnerregister_altmode().

Fix this by validating that pmdata->svidindex is non-negative and strictly less than pmdata->nsvids before accessing the pmdata->svids array inside svdmconsume_modes().

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64330.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
4ab8c18d4d67321cc7b660559de17511d4fc0237
Fixed
89ff289cbf5d3b659a2babc5ccaae4eaf7e7cf53
Fixed
d638ec188e95fe60f4b01106ffd41958f8fb3c2c
Fixed
f8163c414de8640f2ca82ce4dc93409d4cdc2fad
Fixed
012406f89abc52d1d5f07aa5653b519ebf6d2407
Fixed
c6d2af3b217a525741c472f0ab45d7d274b8468f
Fixed
3e1b1ac47e8163627f159f30d80d51b914620dd4
Fixed
313ca06e7e224ca1dfadd5722fe71fb8bc276b8b
Fixed
7b681dd5fbf60b24a13c14661e5b7735759fb491

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64330.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.19.0
Fixed
5.10.261
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.96
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.39
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64330.json"