CVE-2026-64565

Source
https://cve.org/CVERecord?id=CVE-2026-64565
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64565.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-64565
Downstream
Published
2026-08-04T06:23:24.089Z
Modified
2026-08-06T03:48:34.470996179Z
Summary
Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data()
Details

In the Linux kernel, the following vulnerability has been resolved:

Input: ims-pcu - fix heap-buffer-overflow in imspcuprocess_data()

The ims_pcu_process_data() processes incoming URB data byte by byte. However, it fails to check if the read_pos index exceeds IMSPCUBUF_SIZE.

If a malicious USB device sends a packet larger than IMSPCUBUF_SIZE, read_pos will increment indefinitely. Moreover, since read_pos is located immediately after read_buf, the attacker can overwrite read_pos itself to arbitrarily control the index.

This manipulated read_pos is subsequently used in ims_pcu_handle_response() to copy data into cmd_buf, leading to a heap buffer overflow.

Specifically, an attacker can overwrite the cmd_done.wait.head located at offset 136 relative to cmd_buf in the ims_pcu_handle_response(). Consequently, when the driver calls complete(&pcu->cmd_done), it triggers a control flow hijack by using the manipulated pointer.

Fix this by adding a bounds check for read_pos before writing to read_buf. If the packet is too long, discard it, log a warning, and reset the parser state.

[dtor: factor out resetting packet state, reset checksum as well]

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64565.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
628329d52474323938a03826941e166bc7c8eff4
Fixed
40bbbf2e91fd60715525bf0405c67876af817edf
Fixed
ca9f8c09845fb8c51b6d447f6428eecd1b8b0a49
Fixed
d03a740e087de7dcb2a26dc1123377bd3d1d84ca
Fixed
875115b82c295277b81b6dfee7debc725f44e854

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64565.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.10.0
Fixed
6.6.148
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.101
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.42

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64565.json"