CVE-2026-72483
usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control()
Description
In the Linux kernel, the following vulnerability has been resolved: usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control() The `max3421_hub_control()` function handles USB hub class requests to the virtual root hub. In the `default` branches of both the `ClearPortFeature` and `SetPortFeature` switch statements, it modifies `max3421_hcd->port_status` by left shifting 1 by the request's `value` parameter. However, it does not validate whether this shift will exceed the width of `port_status`. So if a malicious userspace task with access to the root hub via /dev/bus/usb/.../001 issues a USBDEVFS_CONTROL ioctl with `wValue` greater than or equal to 32, the left shift operation invokes shift-out-of-bounds undefined behavior. This results in arbitrary bit corruption of `port_status`, including the normally-immutable change bits, which can bypass internal state checks and confuse the hub status. Fix this by rejecting requests whose `value` exceeds the shift width before performing the shift. This issue was found using a KLEE-based symbolic execution tool for kernel drivers that I'm currently developing.
INFO
Published Date :
Aug. 15, 2026, 6:22 a.m.
Last Modified :
Aug. 17, 2026, 6:19 a.m.
Remotely Exploit :
No
Source :
416baaa9-dc9f-4396-8d5f-8c081fb06d67
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS 3.1 | HIGH | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
Solution
- Validate request values before performing bit shifts.
- Reject requests where value exceeds shift width.
- Apply the provided kernel patch.
- Update the Linux kernel.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2026-72483.
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2026-72483 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2026-72483
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-72483 vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2026-72483 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Aug. 17, 2026
Action Type Old Value New Value Added CVSS V3.1 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Changed Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '2d53139f31626bad6f8983d8e519ddde2cbba921', 'lessThan': 'e5fa9d8f40746ec3447335c9642c03410f5fd3af', 'versionType': 'git'}, {'status': 'affected', 'version': '2d53139f31626bad6f8983d8e519ddde2cbba921', 'lessThan': '08b1d4cab0230697bc74c63fc4e40170a7559c54', 'versionType': 'git'}, {'status': 'affected', 'version': '2d53139f31626bad6f8983d8e519ddde2cbba921', 'lessThan': '3be5f24e8270ba53b3c814d13689bb8644c86237', 'versionType': 'git'}, {'status': 'affected', 'version': '2d53139f31626bad6f8983d8e519ddde2cbba921', 'lessThan': 'd512bdefd241b98f4d7bcb5bab5614a86411fad4', 'versionType': 'git'}, {'status': 'affected', 'version': '2d53139f31626bad6f8983d8e519ddde2cbba921', 'lessThan': '00dd025324b56d39d37e57a08f473dab3a660f30', 'versionType': 'git'}, {'status': 'affected', 'version': '2d53139f31626bad6f8983d8e519ddde2cbba921', 'lessThan': '02d03c61e8a7b016956acb48e8a2512d16d87517', 'versionType': 'git'}, {'status': 'affected', 'version': '2d53139f31626bad6f8983d8e519ddde2cbba921', 'lessThan': '4da073d57176d8e1c2bca34febfbc81d2560c1a5', 'versionType': 'git'}, {'status': 'affected', 'version': '2d53139f31626bad6f8983d8e519ddde2cbba921', 'lessThan': 'cff06b03b530ae1fe8a13e93a7848f2130e00fb4', 'versionType': 'git'}], 'programFiles': ['drivers/usb/host/max3421-hcd.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '3.16'}, {'status': 'unaffected', 'version': '0', 'lessThan': '3.16', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.10.261', 'versionType': 'semver', 'lessThanOrEqual': '5.10.*'}, {'status': 'unaffected', 'version': '5.15.212', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.178', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.97', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.40', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.5', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/usb/host/max3421-hcd.c'], 'defaultStatus': 'affected'}] [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '2d53139f31626bad6f8983d8e519ddde2cbba921', 'lessThan': 'e5fa9d8f40746ec3447335c9642c03410f5fd3af', 'versionType': 'git'}, {'status': 'affected', 'version': '2d53139f31626bad6f8983d8e519ddde2cbba921', 'lessThan': '08b1d4cab0230697bc74c63fc4e40170a7559c54', 'versionType': 'git'}, {'status': 'affected', 'version': '2d53139f31626bad6f8983d8e519ddde2cbba921', 'lessThan': '3be5f24e8270ba53b3c814d13689bb8644c86237', 'versionType': 'git'}, {'status': 'affected', 'version': '2d53139f31626bad6f8983d8e519ddde2cbba921', 'lessThan': 'd512bdefd241b98f4d7bcb5bab5614a86411fad4', 'versionType': 'git'}, {'status': 'affected', 'version': '2d53139f31626bad6f8983d8e519ddde2cbba921', 'lessThan': '00dd025324b56d39d37e57a08f473dab3a660f30', 'versionType': 'git'}, {'status': 'affected', 'version': '2d53139f31626bad6f8983d8e519ddde2cbba921', 'lessThan': '02d03c61e8a7b016956acb48e8a2512d16d87517', 'versionType': 'git'}, {'status': 'affected', 'version': '2d53139f31626bad6f8983d8e519ddde2cbba921', 'lessThan': '4da073d57176d8e1c2bca34febfbc81d2560c1a5', 'versionType': 'git'}, {'status': 'affected', 'version': '2d53139f31626bad6f8983d8e519ddde2cbba921', 'lessThan': 'cff06b03b530ae1fe8a13e93a7848f2130e00fb4', 'versionType': 'git'}], 'programFiles': ['drivers/usb/host/max3421-hcd.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '3.16'}, {'status': 'unaffected', 'version': '0', 'lessThan': '3.16', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.10.261', 'versionType': 'semver', 'lessThanOrEqual': '5.10.*'}, {'status': 'unaffected', 'version': '5.15.212', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.178', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.97', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.40', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.5', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/usb/host/max3421-hcd.c'], 'defaultStatus': 'affected'}] -
New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Aug. 15, 2026
Action Type Old Value New Value Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '2d53139f31626bad6f8983d8e519ddde2cbba921', 'lessThan': 'e5fa9d8f40746ec3447335c9642c03410f5fd3af', 'versionType': 'git'}, {'status': 'affected', 'version': '2d53139f31626bad6f8983d8e519ddde2cbba921', 'lessThan': '08b1d4cab0230697bc74c63fc4e40170a7559c54', 'versionType': 'git'}, {'status': 'affected', 'version': '2d53139f31626bad6f8983d8e519ddde2cbba921', 'lessThan': '3be5f24e8270ba53b3c814d13689bb8644c86237', 'versionType': 'git'}, {'status': 'affected', 'version': '2d53139f31626bad6f8983d8e519ddde2cbba921', 'lessThan': 'd512bdefd241b98f4d7bcb5bab5614a86411fad4', 'versionType': 'git'}, {'status': 'affected', 'version': '2d53139f31626bad6f8983d8e519ddde2cbba921', 'lessThan': '00dd025324b56d39d37e57a08f473dab3a660f30', 'versionType': 'git'}, {'status': 'affected', 'version': '2d53139f31626bad6f8983d8e519ddde2cbba921', 'lessThan': '02d03c61e8a7b016956acb48e8a2512d16d87517', 'versionType': 'git'}, {'status': 'affected', 'version': '2d53139f31626bad6f8983d8e519ddde2cbba921', 'lessThan': '4da073d57176d8e1c2bca34febfbc81d2560c1a5', 'versionType': 'git'}, {'status': 'affected', 'version': '2d53139f31626bad6f8983d8e519ddde2cbba921', 'lessThan': 'cff06b03b530ae1fe8a13e93a7848f2130e00fb4', 'versionType': 'git'}], 'programFiles': ['drivers/usb/host/max3421-hcd.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '3.16'}, {'status': 'unaffected', 'version': '0', 'lessThan': '3.16', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.10.261', 'versionType': 'semver', 'lessThanOrEqual': '5.10.*'}, {'status': 'unaffected', 'version': '5.15.212', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.178', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.97', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.40', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.5', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/usb/host/max3421-hcd.c'], 'defaultStatus': 'affected'}] Added Description In the Linux kernel, the following vulnerability has been resolved: usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control() The `max3421_hub_control()` function handles USB hub class requests to the virtual root hub. In the `default` branches of both the `ClearPortFeature` and `SetPortFeature` switch statements, it modifies `max3421_hcd->port_status` by left shifting 1 by the request's `value` parameter. However, it does not validate whether this shift will exceed the width of `port_status`. So if a malicious userspace task with access to the root hub via /dev/bus/usb/.../001 issues a USBDEVFS_CONTROL ioctl with `wValue` greater than or equal to 32, the left shift operation invokes shift-out-of-bounds undefined behavior. This results in arbitrary bit corruption of `port_status`, including the normally-immutable change bits, which can bypass internal state checks and confuse the hub status. Fix this by rejecting requests whose `value` exceeds the shift width before performing the shift. This issue was found using a KLEE-based symbolic execution tool for kernel drivers that I'm currently developing. Added Reference https://git.kernel.org/stable/c/00dd025324b56d39d37e57a08f473dab3a660f30 Added Reference https://git.kernel.org/stable/c/02d03c61e8a7b016956acb48e8a2512d16d87517 Added Reference https://git.kernel.org/stable/c/08b1d4cab0230697bc74c63fc4e40170a7559c54 Added Reference https://git.kernel.org/stable/c/3be5f24e8270ba53b3c814d13689bb8644c86237 Added Reference https://git.kernel.org/stable/c/4da073d57176d8e1c2bca34febfbc81d2560c1a5 Added Reference https://git.kernel.org/stable/c/cff06b03b530ae1fe8a13e93a7848f2130e00fb4 Added Reference https://git.kernel.org/stable/c/d512bdefd241b98f4d7bcb5bab5614a86411fad4 Added Reference https://git.kernel.org/stable/c/e5fa9d8f40746ec3447335c9642c03410f5fd3af