CVE-2026-64330

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/07/2026
Last modified:
25/07/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> usb: typec: tcpm: Validate SVID index in svdm_consume_modes()<br /> <br /> In svdm_consume_modes(), the SVID value is read from pmdata-&gt;svids using<br /> pmdata-&gt;svid_index as an array index without bounds validation:<br /> <br /> paltmode-&gt;svid = pmdata-&gt;svids[pmdata-&gt;svid_index];<br /> <br /> If pmdata-&gt;svid_index is driven beyond SVID_DISCOVERY_MAX (16), it results<br /> in an out-of-bounds read of the pmdata-&gt;svids array. Because pd_mode_data<br /> is embedded inside struct tcpm_port, indexing past svids reads into<br /> adjacent fields. In particular:<br /> - At index 16, it reads the altmodes count.<br /> - At index 18 and beyond, it reads into altmode_desc[], which contains<br /> partner-supplied SVDM Discovery Modes VDOs.<br /> <br /> By injecting a chosen SVID into altmode_desc[0].vdo and driving svid_index<br /> to 20, the partner can force paltmode-&gt;svid to be loaded with an arbitrary,<br /> partner- chosen SVID, which is then registered via<br /> typec_partner_register_altmode().<br /> <br /> Fix this by validating that pmdata-&gt;svid_index is non-negative and strictly<br /> less than pmdata-&gt;nsvids before accessing the pmdata-&gt;svids array inside<br /> svdm_consume_modes().

Impact