GHSA-4m78-mjgq-hq8gunknown

In the Linux kernel, the following vulnerability has been resolved: USB: serial: cypress_m8: fix...

Published
July 19, 2026
Last Modified
July 19, 2026

🔗 CVE IDs covered (1)

📋 Description

In the Linux kernel, the following vulnerability has been resolved:

USB: serial: cypress_m8: fix memory corruption with small endpoint

Make sure that the interrupt-out endpoint max packet size is at least eight bytes to avoid user-controlled slab corruption or NULL-pointer dereference should a malicious device report a smaller size.

🔗 References (10)