CVE-2026-64336

Source
https://cve.org/CVERecord?id=CVE-2026-64336
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-64336.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-64336
Downstream
Related
Published
2026-07-25T08:50:01Z
Modified
2026-09-05T03:30:31Z
Summary
USB: serial: keyspan_pda: fix information leak
Details

In the Linux kernel, the following vulnerability has been resolved:

USB: serial: keyspan_pda: fix information leak

The write() callback is supposed to return the number of characters accepted or a negative errno. Since the addition of write fifo support the keyspan_pda implementation will however return the number characters submitted to the device if the write urb is not already in use. If this number is larger than the number of characters passed to write(), the line discipline continues writing data from beyond the tty write buffer.

Fix the information leak by making sure that keyspan_pda_write_start() returns zero on success as intended.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64336.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
02407bc7d42347da7ed2a3926a0b824bfc614914
Fixed
cccef1711efbcdbe999738ac27d37b9ef6271abd
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
034e38e8f68767fb5438ae3e608ee82919674177
Fixed
b069b7029862fafaff331d4c664d97d4ae828d6d
Fixed
e52ca411f50539ff1d0c877b9312771ca8a858c1
Fixed
2f7a6b8ab3845bd1da02604f1a874b52a4555a72
Fixed
e1494191a3aac665d3a2fce16169a97c346253ec
Fixed
cf6ca0aefae03958cfb5b189b0adbfb25c06bfac
Fixed
d4b12b6b395e43a2b1d80be3745631fcaa9c047b
Fixed
6bfc8d01ac4068eced509f8fc74d0cd205e4dcec

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-64336.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.96
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.39
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.4

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-64336.json"