CVE-2026-64333
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/07/2026
Last modified:
27/07/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
USB: serial: digi_acceleport: fix write buffer corruption<br />
<br />
The digi_write_inb_command() is supposed to wait for the write urb to<br />
become available or return an error, but instead it updates the transfer<br />
buffer and tries to resubmit the urb on timeout.<br />
<br />
To make things worse, for commands like break control where no timeout<br />
is used, the driver would corrupt the urb immediately due to a broken<br />
jiffies comparison (on 32-bit machines this takes five minutes of uptime<br />
to trigger due to INITIAL_JIFFIES).<br />
<br />
Fix this by adding the missing return on timeout and waiting<br />
indefinitely when no timeout has been specified as intended.<br />
<br />
This issue was (sort of) flagged by Sashiko when reviewing an unrelated<br />
change to the driver.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/1243f120790042c2ac92e84e797dacc75fff4366
- https://git.kernel.org/stable/c/24ca1fea8f2753bf33e1d458ec1ae5d9b7796a65
- https://git.kernel.org/stable/c/2f296974acc279f05f284441bfe3064074958d11
- https://git.kernel.org/stable/c/5d9dc88bdf8897788b0eed57113e9eca7fd42ea9
- https://git.kernel.org/stable/c/699dfb6917503b3cda4d5da6941cf79c3c1b4c8b
- https://git.kernel.org/stable/c/a274b3794fe1852c3d9fe6d900b94053c0b03410
- https://git.kernel.org/stable/c/a3a13fdc53103b07335918e2cdeb465038a71725
- https://git.kernel.org/stable/c/e60e4873e9178da9f4f2674e4c2ff085d5a84f79



