Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

In the Linux kernel, the following vulnerability has been resolved: USB: serial: digi_acceleport: fix write buffer corruption The… (CVE-2026-64333)

0
Medium
Published: 07/25/2026 (07/25/2026, 12:31:31 UTC)
Source: GCVE Database

Description

A vulnerability in the Linux kernel's USB serial driver for digi_acceleport was fixed. The issue involved write buffer corruption caused by improper handling of write URB availability and timeouts. Specifically, the function digi_write_inb_command() failed to return on timeout and incorrectly updated the transfer buffer, leading to corruption. On 32-bit systems, a broken jiffies comparison could cause immediate corruption for certain commands without timeouts. The fix adds the missing return on timeout and correctly waits indefinitely when no timeout is specified.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/25/2026, 23:33:02 UTC

Technical Analysis

The Linux kernel's USB serial driver digi_acceleport had a vulnerability where the digi_write_inb_command() function did not properly handle write URB availability timeouts. Instead of returning an error on timeout, it updated the transfer buffer and attempted to resubmit the URB, causing write buffer corruption. Additionally, for commands without timeouts, a broken jiffies comparison on 32-bit machines could trigger immediate corruption after five minutes of uptime. The patch corrects this by adding the missing return statement on timeout and implementing indefinite waiting when no timeout is specified, preventing buffer corruption.

Potential Impact

This vulnerability could lead to write buffer corruption in the USB serial driver, potentially causing data corruption or instability in affected systems. The issue affects the integrity of data transfers through the digi_acceleport USB serial interface. No known exploits in the wild have been reported.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Users should monitor official Linux kernel updates for the fix addressing this issue. Until patched, avoid using affected USB serial devices if possible.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-92hp-m55f-9hjw
Osv Schema Version
1.4.0
Aliases
["CVE-2026-64333"]
Ecosystems
[]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a65420c9c2644c7f808537a

Added to database: 07/25/2026, 23:09:00 UTC

Last enriched: 07/25/2026, 23:33:02 UTC

Last updated: 07/26/2026, 05:06:31 UTC

Views: 6

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses