0.0
NA
CVE-2026-64330
usb: typec: tcpm: Validate SVID index in svdm_consume_modes()
Description

In the Linux kernel, the following vulnerability has been resolved: usb: typec: tcpm: Validate SVID index in svdm_consume_modes() In svdm_consume_modes(), the SVID value is read from pmdata->svids using pmdata->svid_index as an array index without bounds validation: paltmode->svid = pmdata->svids[pmdata->svid_index]; If pmdata->svid_index is driven beyond SVID_DISCOVERY_MAX (16), it results in an out-of-bounds read of the pmdata->svids array. Because pd_mode_data is embedded inside struct tcpm_port, indexing past svids reads into adjacent fields. In particular: - At index 16, it reads the altmodes count. - At index 18 and beyond, it reads into altmode_desc[], which contains partner-supplied SVDM Discovery Modes VDOs. By injecting a chosen SVID into altmode_desc[0].vdo and driving svid_index to 20, the partner can force paltmode->svid to be loaded with an arbitrary, partner- chosen SVID, which is then registered via typec_partner_register_altmode(). Fix this by validating that pmdata->svid_index is non-negative and strictly less than pmdata->nsvids before accessing the pmdata->svids array inside svdm_consume_modes().

INFO

Published Date :

July 25, 2026, 10:17 a.m.

Last Modified :

Aug. 17, 2026, 5:17 a.m.

Remotely Exploit :

No

Source :

416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Products

The following products are affected by CVE-2026-64330 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Linux linux_kernel
Solution
Validate SVID index in svdm_consume_modes() to prevent out-of-bounds reads.
  • Validate svid_index is non-negative and less than nsvids.
  • Update the Linux kernel to the latest version.
  • Apply relevant security patches for USB Type-C TCPM.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-64330 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-64330 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-64330 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2026-64330 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Aug. 17, 2026

    Action Type Old Value New Value
    Changed Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '4ab8c18d4d67321cc7b660559de17511d4fc0237', 'lessThan': '89ff289cbf5d3b659a2babc5ccaae4eaf7e7cf53', 'versionType': 'git'}, {'status': 'affected', 'version': '4ab8c18d4d67321cc7b660559de17511d4fc0237', 'lessThan': 'd638ec188e95fe60f4b01106ffd41958f8fb3c2c', 'versionType': 'git'}, {'status': 'affected', 'version': '4ab8c18d4d67321cc7b660559de17511d4fc0237', 'lessThan': 'f8163c414de8640f2ca82ce4dc93409d4cdc2fad', 'versionType': 'git'}, {'status': 'affected', 'version': '4ab8c18d4d67321cc7b660559de17511d4fc0237', 'lessThan': '012406f89abc52d1d5f07aa5653b519ebf6d2407', 'versionType': 'git'}, {'status': 'affected', 'version': '4ab8c18d4d67321cc7b660559de17511d4fc0237', 'lessThan': 'c6d2af3b217a525741c472f0ab45d7d274b8468f', 'versionType': 'git'}, {'status': 'affected', 'version': '4ab8c18d4d67321cc7b660559de17511d4fc0237', 'lessThan': '3e1b1ac47e8163627f159f30d80d51b914620dd4', 'versionType': 'git'}, {'status': 'affected', 'version': '4ab8c18d4d67321cc7b660559de17511d4fc0237', 'lessThan': '313ca06e7e224ca1dfadd5722fe71fb8bc276b8b', 'versionType': 'git'}, {'status': 'affected', 'version': '4ab8c18d4d67321cc7b660559de17511d4fc0237', 'lessThan': '7b681dd5fbf60b24a13c14661e5b7735759fb491', 'versionType': 'git'}], 'programFiles': ['drivers/usb/typec/tcpm/tcpm.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '4.19'}, {'status': 'unaffected', 'version': '0', 'lessThan': '4.19', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.10.261', 'versionType': 'semver', 'lessThanOrEqual': '5.10.*'}, {'status': 'unaffected', 'version': '5.15.212', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.178', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.96', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.39', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.4', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc3', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/usb/typec/tcpm/tcpm.c'], 'defaultStatus': 'affected'}] [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '4ab8c18d4d67321cc7b660559de17511d4fc0237', 'lessThan': '89ff289cbf5d3b659a2babc5ccaae4eaf7e7cf53', 'versionType': 'git'}, {'status': 'affected', 'version': '4ab8c18d4d67321cc7b660559de17511d4fc0237', 'lessThan': 'd638ec188e95fe60f4b01106ffd41958f8fb3c2c', 'versionType': 'git'}, {'status': 'affected', 'version': '4ab8c18d4d67321cc7b660559de17511d4fc0237', 'lessThan': 'f8163c414de8640f2ca82ce4dc93409d4cdc2fad', 'versionType': 'git'}, {'status': 'affected', 'version': '4ab8c18d4d67321cc7b660559de17511d4fc0237', 'lessThan': '012406f89abc52d1d5f07aa5653b519ebf6d2407', 'versionType': 'git'}, {'status': 'affected', 'version': '4ab8c18d4d67321cc7b660559de17511d4fc0237', 'lessThan': 'c6d2af3b217a525741c472f0ab45d7d274b8468f', 'versionType': 'git'}, {'status': 'affected', 'version': '4ab8c18d4d67321cc7b660559de17511d4fc0237', 'lessThan': '3e1b1ac47e8163627f159f30d80d51b914620dd4', 'versionType': 'git'}, {'status': 'affected', 'version': '4ab8c18d4d67321cc7b660559de17511d4fc0237', 'lessThan': '313ca06e7e224ca1dfadd5722fe71fb8bc276b8b', 'versionType': 'git'}, {'status': 'affected', 'version': '4ab8c18d4d67321cc7b660559de17511d4fc0237', 'lessThan': '7b681dd5fbf60b24a13c14661e5b7735759fb491', 'versionType': 'git'}], 'programFiles': ['drivers/usb/typec/tcpm/tcpm.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '4.19'}, {'status': 'unaffected', 'version': '0', 'lessThan': '4.19', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.10.261', 'versionType': 'semver', 'lessThanOrEqual': '5.10.*'}, {'status': 'unaffected', 'version': '5.15.212', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.178', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.96', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.39', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.4', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/usb/typec/tcpm/tcpm.c'], 'defaultStatus': 'affected'}]
  • New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Jul. 25, 2026

    Action Type Old Value New Value
    Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '4ab8c18d4d67321cc7b660559de17511d4fc0237', 'lessThan': '89ff289cbf5d3b659a2babc5ccaae4eaf7e7cf53', 'versionType': 'git'}, {'status': 'affected', 'version': '4ab8c18d4d67321cc7b660559de17511d4fc0237', 'lessThan': 'd638ec188e95fe60f4b01106ffd41958f8fb3c2c', 'versionType': 'git'}, {'status': 'affected', 'version': '4ab8c18d4d67321cc7b660559de17511d4fc0237', 'lessThan': 'f8163c414de8640f2ca82ce4dc93409d4cdc2fad', 'versionType': 'git'}, {'status': 'affected', 'version': '4ab8c18d4d67321cc7b660559de17511d4fc0237', 'lessThan': '012406f89abc52d1d5f07aa5653b519ebf6d2407', 'versionType': 'git'}, {'status': 'affected', 'version': '4ab8c18d4d67321cc7b660559de17511d4fc0237', 'lessThan': 'c6d2af3b217a525741c472f0ab45d7d274b8468f', 'versionType': 'git'}, {'status': 'affected', 'version': '4ab8c18d4d67321cc7b660559de17511d4fc0237', 'lessThan': '3e1b1ac47e8163627f159f30d80d51b914620dd4', 'versionType': 'git'}, {'status': 'affected', 'version': '4ab8c18d4d67321cc7b660559de17511d4fc0237', 'lessThan': '313ca06e7e224ca1dfadd5722fe71fb8bc276b8b', 'versionType': 'git'}, {'status': 'affected', 'version': '4ab8c18d4d67321cc7b660559de17511d4fc0237', 'lessThan': '7b681dd5fbf60b24a13c14661e5b7735759fb491', 'versionType': 'git'}], 'programFiles': ['drivers/usb/typec/tcpm/tcpm.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '4.19'}, {'status': 'unaffected', 'version': '0', 'lessThan': '4.19', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.10.261', 'versionType': 'semver', 'lessThanOrEqual': '5.10.*'}, {'status': 'unaffected', 'version': '5.15.212', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.178', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.96', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.39', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.4', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc3', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/usb/typec/tcpm/tcpm.c'], 'defaultStatus': 'affected'}]
    Added Description In the Linux kernel, the following vulnerability has been resolved: usb: typec: tcpm: Validate SVID index in svdm_consume_modes() In svdm_consume_modes(), the SVID value is read from pmdata->svids using pmdata->svid_index as an array index without bounds validation: paltmode->svid = pmdata->svids[pmdata->svid_index]; If pmdata->svid_index is driven beyond SVID_DISCOVERY_MAX (16), it results in an out-of-bounds read of the pmdata->svids array. Because pd_mode_data is embedded inside struct tcpm_port, indexing past svids reads into adjacent fields. In particular: - At index 16, it reads the altmodes count. - At index 18 and beyond, it reads into altmode_desc[], which contains partner-supplied SVDM Discovery Modes VDOs. By injecting a chosen SVID into altmode_desc[0].vdo and driving svid_index to 20, the partner can force paltmode->svid to be loaded with an arbitrary, partner- chosen SVID, which is then registered via typec_partner_register_altmode(). Fix this by validating that pmdata->svid_index is non-negative and strictly less than pmdata->nsvids before accessing the pmdata->svids array inside svdm_consume_modes().
    Added Reference https://git.kernel.org/stable/c/012406f89abc52d1d5f07aa5653b519ebf6d2407
    Added Reference https://git.kernel.org/stable/c/313ca06e7e224ca1dfadd5722fe71fb8bc276b8b
    Added Reference https://git.kernel.org/stable/c/3e1b1ac47e8163627f159f30d80d51b914620dd4
    Added Reference https://git.kernel.org/stable/c/7b681dd5fbf60b24a13c14661e5b7735759fb491
    Added Reference https://git.kernel.org/stable/c/89ff289cbf5d3b659a2babc5ccaae4eaf7e7cf53
    Added Reference https://git.kernel.org/stable/c/c6d2af3b217a525741c472f0ab45d7d274b8468f
    Added Reference https://git.kernel.org/stable/c/d638ec188e95fe60f4b01106ffd41958f8fb3c2c
    Added Reference https://git.kernel.org/stable/c/f8163c414de8640f2ca82ce4dc93409d4cdc2fad
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.