In the Linux kernel, the following vulnerability has been resolved: USB: serial: digi_acceleport: fix write buffer corruption The… (CVE-2026-64333)
A vulnerability in the Linux kernel's USB serial driver for digi_acceleport was fixed. The issue involved write buffer corruption caused by improper handling of write URB availability and timeouts. Specifically, the function digi_write_inb_command() failed to return on timeout and incorrectly updated the transfer buffer, leading to corruption. On 32-bit systems, a broken jiffies comparison could cause immediate corruption for certain commands without timeouts. The fix adds the missing return on timeout and correctly waits indefinitely when no timeout is specified.
AI Analysis
Technical Summary
The Linux kernel's USB serial driver digi_acceleport had a vulnerability where the digi_write_inb_command() function did not properly handle write URB availability timeouts. Instead of returning an error on timeout, it updated the transfer buffer and attempted to resubmit the URB, causing write buffer corruption. Additionally, for commands without timeouts, a broken jiffies comparison on 32-bit machines could trigger immediate corruption after five minutes of uptime. The patch corrects this by adding the missing return statement on timeout and implementing indefinite waiting when no timeout is specified, preventing buffer corruption.
Potential Impact
This vulnerability could lead to write buffer corruption in the USB serial driver, potentially causing data corruption or instability in affected systems. The issue affects the integrity of data transfers through the digi_acceleport USB serial interface. No known exploits in the wild have been reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Users should monitor official Linux kernel updates for the fix addressing this issue. Until patched, avoid using affected USB serial devices if possible.
In the Linux kernel, the following vulnerability has been resolved: USB: serial: digi_acceleport: fix write buffer corruption The… (CVE-2026-64333)
Description
A vulnerability in the Linux kernel's USB serial driver for digi_acceleport was fixed. The issue involved write buffer corruption caused by improper handling of write URB availability and timeouts. Specifically, the function digi_write_inb_command() failed to return on timeout and incorrectly updated the transfer buffer, leading to corruption. On 32-bit systems, a broken jiffies comparison could cause immediate corruption for certain commands without timeouts. The fix adds the missing return on timeout and correctly waits indefinitely when no timeout is specified.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel's USB serial driver digi_acceleport had a vulnerability where the digi_write_inb_command() function did not properly handle write URB availability timeouts. Instead of returning an error on timeout, it updated the transfer buffer and attempted to resubmit the URB, causing write buffer corruption. Additionally, for commands without timeouts, a broken jiffies comparison on 32-bit machines could trigger immediate corruption after five minutes of uptime. The patch corrects this by adding the missing return statement on timeout and implementing indefinite waiting when no timeout is specified, preventing buffer corruption.
Potential Impact
This vulnerability could lead to write buffer corruption in the USB serial driver, potentially causing data corruption or instability in affected systems. The issue affects the integrity of data transfers through the digi_acceleport USB serial interface. No known exploits in the wild have been reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Users should monitor official Linux kernel updates for the fix addressing this issue. Until patched, avoid using affected USB serial devices if possible.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-92hp-m55f-9hjw
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-64333"]
- Ecosystems
- []
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a65420c9c2644c7f808537a
Added to database: 07/25/2026, 23:09:00 UTC
Last enriched: 07/25/2026, 23:33:02 UTC
Last updated: 07/26/2026, 05:06:31 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.