{
  "threat_severity" : "Moderate",
  "public_date" : "2026-06-25T00:00:00Z",
  "bugzilla" : {
    "description" : "kernel: USB: serial: io_ti: fix heap overflow in get_manuf_info()",
    "id" : "2492750",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2492750"
  },
  "cvss3" : {
    "cvss3_base_score" : "6.8",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-787",
  "details" : [ "In the Linux kernel, the following vulnerability has been resolved:\nUSB: serial: io_ti: fix heap overflow in get_manuf_info()\nget_manuf_info() reads le16_to_cpu(rom_desc->Size) bytes from the\ndevice I2C EEPROM into a buffer allocated with kmalloc_obj(), which\nis sizeof(struct edge_ti_manuf_descriptor) = 10 bytes.\nThe Size field comes from the device and is only validated (in\ncheck_i2c_image()) to make sure the descriptor fits within\nTI_MAX_I2C_SIZE (16384 bytes), not against the destination buffer size.\nA malicious USB device can therefore set Size to any value up to 16377,\ncausing a heap overflow of up to 16367 bytes when plugged into a host\nrunning this driver.\nvalid_csum() is called after read_rom() and also iterates\nbuffer[0..Size-1], compounding the out-of-bounds access.\nFix by rejecting descriptors with unexpected length before calling\nread_rom().\n[ johan: amend commit message; also check for short descriptors ]", "A flaw was found in the Linux kernel's `io_ti` USB serial driver. A malicious USB device, when plugged into a host running this driver, can exploit a heap overflow vulnerability in the `get_manuf_info()` function. This occurs because the driver does not properly validate the size of data read from the device's I2C EEPROM against the allocated memory buffer. This improper validation can lead to out-of-bounds memory writes, potentially allowing an attacker to execute arbitrary code or cause a system crash (Denial of Service)." ],
  "statement" : "get_manuf_info() in the USB serial io_ti driver can copy a device controlled EEPROM descriptor length into a 10 byte heap buffer without checking that the descriptor Size matches sizeof(struct edge_ti_manuf_descriptor). A malicious USB device can advertise a Size value up to the TI I2C image limit and trigger a large heap overflow when the device is attached and the driver reads the descriptor. For the CVSS the PR:N is used because the attacker does not need an account on the host and only needs the malicious USB device to be processed by the vulnerable driver. Impact is at least kernel crash DoS and because this is a kernel heap overflow with device controlled input, confidentiality and integrity impact are plausible in worst case.",
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 10",
    "release_date" : "2026-09-01T00:00:00Z",
    "advisory" : "RHSA-2026:61887",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10.2",
    "package" : "kernel-0:6.12.0-211.50.1.el10_2"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Not affected",
    "package_name" : "kernel",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "fix_state" : "Affected",
    "package_name" : "kernel",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "fix_state" : "Affected",
    "package_name" : "kernel-rt",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Affected",
    "package_name" : "kernel",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Affected",
    "package_name" : "kernel-rt",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "fix_state" : "Affected",
    "package_name" : "kernel",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "fix_state" : "Affected",
    "package_name" : "kernel-rt",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-53196\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-53196\nhttps://lore.kernel.org/linux-cve-announce/2026062559-CVE-2026-53196-bcc6@gregkh/T" ],
  "name" : "CVE-2026-53196",
  "mitigation" : {
    "value" : "To mitigate this issue, prevent module io_ti from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically.",
    "lang" : "en:us"
  },
  "csaw" : false
}