๐Ÿ” CVE Alert

CVE-2026-63903

UNKNOWN 0.0

USB: serial: belkin_sa: validate interrupt status length

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: USB: serial: belkin_sa: validate interrupt status length The Belkin interrupt callback treats interrupt data as a four-byte status report and reads LSR/MSR fields at offsets 2 and 3. The interrupt-in buffer length is derived from endpoint wMaxPacketSize, and short interrupt transfers may complete successfully with a smaller actual_length. Check the completed interrupt packet length before parsing status fields so short interrupt endpoints and short successful packets are ignored instead of causing out-of-bounds or stale status-byte reads. KASAN report as below: BUG: KASAN: slab-out-of-bounds in belkin_sa_read_int_callback() Read of size 1 Call trace: belkin_sa_read_int_callback() (drivers/usb/serial/belkin_sa.c:202) __usb_hcd_giveback_urb() (drivers/usb/core/hcd.c:1630) dummy_timer() (?:?)

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jul 19, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < f1617539ab90e67da788959bfd314076f093a11a 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < f361359a952da15e70e693c2d7dca5c5843eae3e 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 37e54d1b986df35c936d81e5b59a7aa3ec6938f0 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < ffb739a49186ea784bbd9cb91b647f062395b419 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 6a4602221cba7a738442328d66a2f0b1c9bf6e17 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 22823a319fb2afdf02cacafbed8b613b757efbc8 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < db1e7eb6203d534dad64cac2c793b69e561e657b 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 4ce058df2ee02cc2a0f0fd5cd64ce6f1482a0b65
Linux / Linux
2.6.12

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/f1617539ab90e67da788959bfd314076f093a11a git.kernel.org: https://git.kernel.org/stable/c/f361359a952da15e70e693c2d7dca5c5843eae3e git.kernel.org: https://git.kernel.org/stable/c/37e54d1b986df35c936d81e5b59a7aa3ec6938f0 git.kernel.org: https://git.kernel.org/stable/c/ffb739a49186ea784bbd9cb91b647f062395b419 git.kernel.org: https://git.kernel.org/stable/c/6a4602221cba7a738442328d66a2f0b1c9bf6e17 git.kernel.org: https://git.kernel.org/stable/c/22823a319fb2afdf02cacafbed8b613b757efbc8 git.kernel.org: https://git.kernel.org/stable/c/db1e7eb6203d534dad64cac2c793b69e561e657b git.kernel.org: https://git.kernel.org/stable/c/4ce058df2ee02cc2a0f0fd5cd64ce6f1482a0b65