In the Linux kernel, the following vulnerability has been resolved: USB: serial: keyspan_pda: fix information leak The write() callback is supposed… (CVE-2026-64336)
A vulnerability in the Linux kernel's USB serial driver for keyspan_pda devices could cause an information leak. The issue arises because the write() callback may return a number larger than the number of characters passed, causing the system to read beyond the intended buffer. This flaw was fixed by ensuring the write callback returns zero on success as intended.
AI Analysis
Technical Summary
The Linux kernel USB serial driver keyspan_pda had a flaw in its write() callback implementation. After adding write FIFO support, the driver could return a count of characters submitted to the device that exceeded the number actually passed to write(). This caused the line discipline to continue writing data beyond the tty write buffer, resulting in an information leak. The fix ensures that keyspan_pda_write_start() returns zero on success, preventing the leak.
Potential Impact
This vulnerability could lead to an information leak by allowing data beyond the intended write buffer to be read or transmitted. There is no indication of code execution or privilege escalation. No known exploits are reported in the wild.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The description states the issue has been resolved, implying a fix is available in updated Linux kernel versions. Users should apply official kernel updates once available.
In the Linux kernel, the following vulnerability has been resolved: USB: serial: keyspan_pda: fix information leak The write() callback is supposed… (CVE-2026-64336)
Description
A vulnerability in the Linux kernel's USB serial driver for keyspan_pda devices could cause an information leak. The issue arises because the write() callback may return a number larger than the number of characters passed, causing the system to read beyond the intended buffer. This flaw was fixed by ensuring the write callback returns zero on success as intended.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel USB serial driver keyspan_pda had a flaw in its write() callback implementation. After adding write FIFO support, the driver could return a count of characters submitted to the device that exceeded the number actually passed to write(). This caused the line discipline to continue writing data beyond the tty write buffer, resulting in an information leak. The fix ensures that keyspan_pda_write_start() returns zero on success, preventing the leak.
Potential Impact
This vulnerability could lead to an information leak by allowing data beyond the intended write buffer to be read or transmitted. There is no indication of code execution or privilege escalation. No known exploits are reported in the wild.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The description states the issue has been resolved, implying a fix is available in updated Linux kernel versions. Users should apply official kernel updates once available.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-mhg5-fr5x-3g7c
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-64336"]
- Ecosystems
- []
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a65420c9c2644c7f8085051
Added to database: 07/25/2026, 23:09:00 UTC
Last enriched: 07/25/2026, 23:31:59 UTC
Last updated: 07/26/2026, 04:51:29 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.