7.8
HIGH CVSS 3.1
CVE-2026-72483
usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control()
Description

In the Linux kernel, the following vulnerability has been resolved: usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control() The `max3421_hub_control()` function handles USB hub class requests to the virtual root hub. In the `default` branches of both the `ClearPortFeature` and `SetPortFeature` switch statements, it modifies `max3421_hcd->port_status` by left shifting 1 by the request's `value` parameter. However, it does not validate whether this shift will exceed the width of `port_status`. So if a malicious userspace task with access to the root hub via /dev/bus/usb/.../001 issues a USBDEVFS_CONTROL ioctl with `wValue` greater than or equal to 32, the left shift operation invokes shift-out-of-bounds undefined behavior. This results in arbitrary bit corruption of `port_status`, including the normally-immutable change bits, which can bypass internal state checks and confuse the hub status. Fix this by rejecting requests whose `value` exceeds the shift width before performing the shift. This issue was found using a KLEE-based symbolic execution tool for kernel drivers that I'm currently developing.

INFO

Published Date :

Aug. 15, 2026, 6:22 a.m.

Last Modified :

Aug. 17, 2026, 6:19 a.m.

Remotely Exploit :

No

Source :

416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Products

The following products are affected by CVE-2026-72483 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Linux linux_kernel
CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 3.1 HIGH 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Solution
Address shift-out-of-bounds in max3421_hub_control by validating input values.
  • Validate request values before performing bit shifts.
  • Reject requests where value exceeds shift width.
  • Apply the provided kernel patch.
  • Update the Linux kernel.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-72483 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-72483 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-72483 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2026-72483 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Aug. 17, 2026

    Action Type Old Value New Value
    Added CVSS V3.1 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
    Changed Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '2d53139f31626bad6f8983d8e519ddde2cbba921', 'lessThan': 'e5fa9d8f40746ec3447335c9642c03410f5fd3af', 'versionType': 'git'}, {'status': 'affected', 'version': '2d53139f31626bad6f8983d8e519ddde2cbba921', 'lessThan': '08b1d4cab0230697bc74c63fc4e40170a7559c54', 'versionType': 'git'}, {'status': 'affected', 'version': '2d53139f31626bad6f8983d8e519ddde2cbba921', 'lessThan': '3be5f24e8270ba53b3c814d13689bb8644c86237', 'versionType': 'git'}, {'status': 'affected', 'version': '2d53139f31626bad6f8983d8e519ddde2cbba921', 'lessThan': 'd512bdefd241b98f4d7bcb5bab5614a86411fad4', 'versionType': 'git'}, {'status': 'affected', 'version': '2d53139f31626bad6f8983d8e519ddde2cbba921', 'lessThan': '00dd025324b56d39d37e57a08f473dab3a660f30', 'versionType': 'git'}, {'status': 'affected', 'version': '2d53139f31626bad6f8983d8e519ddde2cbba921', 'lessThan': '02d03c61e8a7b016956acb48e8a2512d16d87517', 'versionType': 'git'}, {'status': 'affected', 'version': '2d53139f31626bad6f8983d8e519ddde2cbba921', 'lessThan': '4da073d57176d8e1c2bca34febfbc81d2560c1a5', 'versionType': 'git'}, {'status': 'affected', 'version': '2d53139f31626bad6f8983d8e519ddde2cbba921', 'lessThan': 'cff06b03b530ae1fe8a13e93a7848f2130e00fb4', 'versionType': 'git'}], 'programFiles': ['drivers/usb/host/max3421-hcd.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '3.16'}, {'status': 'unaffected', 'version': '0', 'lessThan': '3.16', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.10.261', 'versionType': 'semver', 'lessThanOrEqual': '5.10.*'}, {'status': 'unaffected', 'version': '5.15.212', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.178', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.97', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.40', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.5', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/usb/host/max3421-hcd.c'], 'defaultStatus': 'affected'}] [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '2d53139f31626bad6f8983d8e519ddde2cbba921', 'lessThan': 'e5fa9d8f40746ec3447335c9642c03410f5fd3af', 'versionType': 'git'}, {'status': 'affected', 'version': '2d53139f31626bad6f8983d8e519ddde2cbba921', 'lessThan': '08b1d4cab0230697bc74c63fc4e40170a7559c54', 'versionType': 'git'}, {'status': 'affected', 'version': '2d53139f31626bad6f8983d8e519ddde2cbba921', 'lessThan': '3be5f24e8270ba53b3c814d13689bb8644c86237', 'versionType': 'git'}, {'status': 'affected', 'version': '2d53139f31626bad6f8983d8e519ddde2cbba921', 'lessThan': 'd512bdefd241b98f4d7bcb5bab5614a86411fad4', 'versionType': 'git'}, {'status': 'affected', 'version': '2d53139f31626bad6f8983d8e519ddde2cbba921', 'lessThan': '00dd025324b56d39d37e57a08f473dab3a660f30', 'versionType': 'git'}, {'status': 'affected', 'version': '2d53139f31626bad6f8983d8e519ddde2cbba921', 'lessThan': '02d03c61e8a7b016956acb48e8a2512d16d87517', 'versionType': 'git'}, {'status': 'affected', 'version': '2d53139f31626bad6f8983d8e519ddde2cbba921', 'lessThan': '4da073d57176d8e1c2bca34febfbc81d2560c1a5', 'versionType': 'git'}, {'status': 'affected', 'version': '2d53139f31626bad6f8983d8e519ddde2cbba921', 'lessThan': 'cff06b03b530ae1fe8a13e93a7848f2130e00fb4', 'versionType': 'git'}], 'programFiles': ['drivers/usb/host/max3421-hcd.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '3.16'}, {'status': 'unaffected', 'version': '0', 'lessThan': '3.16', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.10.261', 'versionType': 'semver', 'lessThanOrEqual': '5.10.*'}, {'status': 'unaffected', 'version': '5.15.212', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.178', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.97', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.40', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.5', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/usb/host/max3421-hcd.c'], 'defaultStatus': 'affected'}]
  • New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Aug. 15, 2026

    Action Type Old Value New Value
    Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '2d53139f31626bad6f8983d8e519ddde2cbba921', 'lessThan': 'e5fa9d8f40746ec3447335c9642c03410f5fd3af', 'versionType': 'git'}, {'status': 'affected', 'version': '2d53139f31626bad6f8983d8e519ddde2cbba921', 'lessThan': '08b1d4cab0230697bc74c63fc4e40170a7559c54', 'versionType': 'git'}, {'status': 'affected', 'version': '2d53139f31626bad6f8983d8e519ddde2cbba921', 'lessThan': '3be5f24e8270ba53b3c814d13689bb8644c86237', 'versionType': 'git'}, {'status': 'affected', 'version': '2d53139f31626bad6f8983d8e519ddde2cbba921', 'lessThan': 'd512bdefd241b98f4d7bcb5bab5614a86411fad4', 'versionType': 'git'}, {'status': 'affected', 'version': '2d53139f31626bad6f8983d8e519ddde2cbba921', 'lessThan': '00dd025324b56d39d37e57a08f473dab3a660f30', 'versionType': 'git'}, {'status': 'affected', 'version': '2d53139f31626bad6f8983d8e519ddde2cbba921', 'lessThan': '02d03c61e8a7b016956acb48e8a2512d16d87517', 'versionType': 'git'}, {'status': 'affected', 'version': '2d53139f31626bad6f8983d8e519ddde2cbba921', 'lessThan': '4da073d57176d8e1c2bca34febfbc81d2560c1a5', 'versionType': 'git'}, {'status': 'affected', 'version': '2d53139f31626bad6f8983d8e519ddde2cbba921', 'lessThan': 'cff06b03b530ae1fe8a13e93a7848f2130e00fb4', 'versionType': 'git'}], 'programFiles': ['drivers/usb/host/max3421-hcd.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '3.16'}, {'status': 'unaffected', 'version': '0', 'lessThan': '3.16', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.10.261', 'versionType': 'semver', 'lessThanOrEqual': '5.10.*'}, {'status': 'unaffected', 'version': '5.15.212', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.178', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.97', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.40', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.5', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/usb/host/max3421-hcd.c'], 'defaultStatus': 'affected'}]
    Added Description In the Linux kernel, the following vulnerability has been resolved: usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control() The `max3421_hub_control()` function handles USB hub class requests to the virtual root hub. In the `default` branches of both the `ClearPortFeature` and `SetPortFeature` switch statements, it modifies `max3421_hcd->port_status` by left shifting 1 by the request's `value` parameter. However, it does not validate whether this shift will exceed the width of `port_status`. So if a malicious userspace task with access to the root hub via /dev/bus/usb/.../001 issues a USBDEVFS_CONTROL ioctl with `wValue` greater than or equal to 32, the left shift operation invokes shift-out-of-bounds undefined behavior. This results in arbitrary bit corruption of `port_status`, including the normally-immutable change bits, which can bypass internal state checks and confuse the hub status. Fix this by rejecting requests whose `value` exceeds the shift width before performing the shift. This issue was found using a KLEE-based symbolic execution tool for kernel drivers that I'm currently developing.
    Added Reference https://git.kernel.org/stable/c/00dd025324b56d39d37e57a08f473dab3a660f30
    Added Reference https://git.kernel.org/stable/c/02d03c61e8a7b016956acb48e8a2512d16d87517
    Added Reference https://git.kernel.org/stable/c/08b1d4cab0230697bc74c63fc4e40170a7559c54
    Added Reference https://git.kernel.org/stable/c/3be5f24e8270ba53b3c814d13689bb8644c86237
    Added Reference https://git.kernel.org/stable/c/4da073d57176d8e1c2bca34febfbc81d2560c1a5
    Added Reference https://git.kernel.org/stable/c/cff06b03b530ae1fe8a13e93a7848f2130e00fb4
    Added Reference https://git.kernel.org/stable/c/d512bdefd241b98f4d7bcb5bab5614a86411fad4
    Added Reference https://git.kernel.org/stable/c/e5fa9d8f40746ec3447335c9642c03410f5fd3af
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.