In the Linux kernel, the following vulnerability has been resolved: USB: serial: belkin_sa: validate interrupt status length The Belkin interrupt… (CVE-2026-63903)
A vulnerability in the Linux kernel's USB serial driver for Belkin devices was resolved. The issue involved improper validation of interrupt status length, where the driver assumed a fixed four-byte status report but did not verify the actual length of the interrupt data. This could lead to out-of-bounds reads when short interrupt transfers occurred. The flaw was detected by KASAN as a slab-out-of-bounds read in the belkin_sa_read_int_callback function.
AI Analysis
Technical Summary
The Linux kernel USB serial driver for Belkin devices (belkin_sa) improperly handled interrupt-in buffer lengths by assuming a fixed four-byte status report. The actual interrupt data length is derived from the endpoint's wMaxPacketSize, but short interrupt transfers with smaller actual_length values were not validated before accessing status fields at offsets 2 and 3. This caused out-of-bounds or stale status-byte reads, as confirmed by a KASAN slab-out-of-bounds report in belkin_sa_read_int_callback. The vulnerability was addressed by adding checks on the completed interrupt packet length before parsing status fields, preventing invalid memory access.
Potential Impact
This vulnerability could cause out-of-bounds memory reads in the kernel, potentially leading to kernel crashes or information disclosure. However, no known exploits in the wild have been reported. The impact is limited to systems using the affected USB serial driver for Belkin devices.
Mitigation Recommendations
A fix has been implemented in the Linux kernel to validate interrupt packet lengths before parsing status fields in the belkin_sa driver. Since this is a kernel vulnerability, applying the official Linux kernel updates that include this fix is the recommended remediation. Patch status is not explicitly confirmed in the provided data; users should consult the Linux kernel vendor advisory or update channels for the official fix.
In the Linux kernel, the following vulnerability has been resolved: USB: serial: belkin_sa: validate interrupt status length The Belkin interrupt… (CVE-2026-63903)
Description
A vulnerability in the Linux kernel's USB serial driver for Belkin devices was resolved. The issue involved improper validation of interrupt status length, where the driver assumed a fixed four-byte status report but did not verify the actual length of the interrupt data. This could lead to out-of-bounds reads when short interrupt transfers occurred. The flaw was detected by KASAN as a slab-out-of-bounds read in the belkin_sa_read_int_callback function.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel USB serial driver for Belkin devices (belkin_sa) improperly handled interrupt-in buffer lengths by assuming a fixed four-byte status report. The actual interrupt data length is derived from the endpoint's wMaxPacketSize, but short interrupt transfers with smaller actual_length values were not validated before accessing status fields at offsets 2 and 3. This caused out-of-bounds or stale status-byte reads, as confirmed by a KASAN slab-out-of-bounds report in belkin_sa_read_int_callback. The vulnerability was addressed by adding checks on the completed interrupt packet length before parsing status fields, preventing invalid memory access.
Potential Impact
This vulnerability could cause out-of-bounds memory reads in the kernel, potentially leading to kernel crashes or information disclosure. However, no known exploits in the wild have been reported. The impact is limited to systems using the affected USB serial driver for Belkin devices.
Mitigation Recommendations
A fix has been implemented in the Linux kernel to validate interrupt packet lengths before parsing status fields in the belkin_sa driver. Since this is a kernel vulnerability, applying the official Linux kernel updates that include this fix is the recommended remediation. Patch status is not explicitly confirmed in the provided data; users should consult the Linux kernel vendor advisory or update channels for the official fix.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-5c4f-qfw8-c34w
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-63903"]
- Ecosystems
- []
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a5d27ab2a4a8d598912f945
Added to database: 07/19/2026, 19:38:19 UTC
Last enriched: 07/19/2026, 20:10:27 UTC
Last updated: 07/20/2026, 17:26:47 UTC
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.