In the Linux kernel, the following vulnerability has been resolved: USB: serial: digi_acceleport: fix write buffer corruption The… (CVE-2026-64333)
In the Linux kernel, the following vulnerability has been resolved: USB: serial: digi_acceleport: fix write buffer corruption The digi_write_inb_command() is supposed to wait for the write urb to become available or return an error, but instead it updates the transfer buffer and tries to resubmit the urb on timeout. To make things worse, for commands like break control where no timeout is used, the driver would corrupt the urb immediately due to a broken jiffies comparison (on 32-bit machines this takes five minutes of uptime to trigger due to INITIAL_JIFFIES). Fix this by adding the missing return on timeout and waiting indefinitely when no timeout has been specified as intended. This issue was (sort of) flagged by Sashiko when reviewing an unrelated change to the driver.
AI Analysis
Technical Summary
The Linux kernel's USB serial driver digi_acceleport had a vulnerability where the digi_write_inb_command() function did not properly handle write URB availability timeouts. Instead of returning an error on timeout, it updated the transfer buffer and attempted to resubmit the URB, causing write buffer corruption. Additionally, for commands without timeouts, a broken jiffies comparison on 32-bit machines could trigger immediate corruption after five minutes of uptime. The patch corrects this by adding the missing return statement on timeout and implementing indefinite waiting when no timeout is specified, preventing buffer corruption.
Potential Impact
This vulnerability could lead to write buffer corruption in the USB serial driver, potentially causing data corruption or instability in affected systems. The issue affects the integrity of data transfers through the digi_acceleport USB serial interface. No known exploits in the wild have been reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Users should monitor official Linux kernel updates for the fix addressing this issue. Until patched, avoid using affected USB serial devices if possible.
In the Linux kernel, the following vulnerability has been resolved: USB: serial: digi_acceleport: fix write buffer corruption The… (CVE-2026-64333)
Description
In the Linux kernel, the following vulnerability has been resolved: USB: serial: digi_acceleport: fix write buffer corruption The digi_write_inb_command() is supposed to wait for the write urb to become available or return an error, but instead it updates the transfer buffer and tries to resubmit the urb on timeout. To make things worse, for commands like break control where no timeout is used, the driver would corrupt the urb immediately due to a broken jiffies comparison (on 32-bit machines this takes five minutes of uptime to trigger due to INITIAL_JIFFIES). Fix this by adding the missing return on timeout and waiting indefinitely when no timeout has been specified as intended. This issue was (sort of) flagged by Sashiko when reviewing an unrelated change to the driver.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel's USB serial driver digi_acceleport had a vulnerability where the digi_write_inb_command() function did not properly handle write URB availability timeouts. Instead of returning an error on timeout, it updated the transfer buffer and attempted to resubmit the URB, causing write buffer corruption. Additionally, for commands without timeouts, a broken jiffies comparison on 32-bit machines could trigger immediate corruption after five minutes of uptime. The patch corrects this by adding the missing return statement on timeout and implementing indefinite waiting when no timeout is specified, preventing buffer corruption.
Potential Impact
This vulnerability could lead to write buffer corruption in the USB serial driver, potentially causing data corruption or instability in affected systems. The issue affects the integrity of data transfers through the digi_acceleport USB serial interface. No known exploits in the wild have been reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Users should monitor official Linux kernel updates for the fix addressing this issue. Until patched, avoid using affected USB serial devices if possible.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-92hp-m55f-9hjw
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-64333"]
- Ecosystems
- []
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a65420c9c2644c7f808537a
Added to database: 07/25/2026, 23:09:00 UTC
Last enriched: 07/25/2026, 23:33:02 UTC
Last updated: 09/07/2026, 10:52:10 UTC
Views: 40
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.