{"id":"CVE-2026-64330","summary":"usb: typec: tcpm: Validate SVID index in svdm_consume_modes()","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: tcpm: Validate SVID index in svdm_consume_modes()\n\nIn svdm_consume_modes(), the SVID value is read from pmdata-\u003esvids using\npmdata-\u003esvid_index as an array index without bounds validation:\n\n    paltmode-\u003esvid = pmdata-\u003esvids[pmdata-\u003esvid_index];\n\nIf pmdata-\u003esvid_index is driven beyond SVID_DISCOVERY_MAX (16), it results\nin an out-of-bounds read of the pmdata-\u003esvids array. Because pd_mode_data\nis embedded inside struct tcpm_port, indexing past svids reads into\nadjacent fields. In particular:\n- At index 16, it reads the altmodes count.\n- At index 18 and beyond, it reads into altmode_desc[], which contains\n  partner-supplied SVDM Discovery Modes VDOs.\n\nBy injecting a chosen SVID into altmode_desc[0].vdo and driving svid_index\nto 20, the partner can force paltmode-\u003esvid to be loaded with an arbitrary,\npartner- chosen SVID, which is then registered via\ntypec_partner_register_altmode().\n\nFix this by validating that pmdata-\u003esvid_index is non-negative and strictly\nless than pmdata-\u003ensvids before accessing the pmdata-\u003esvids array inside\nsvdm_consume_modes().","modified":"2026-07-27T04:03:19.894874443Z","published":"2026-07-25T08:49:57.734Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64330.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/012406f89abc52d1d5f07aa5653b519ebf6d2407"},{"type":"WEB","url":"https://git.kernel.org/stable/c/313ca06e7e224ca1dfadd5722fe71fb8bc276b8b"},{"type":"WEB","url":"https://git.kernel.org/stable/c/3e1b1ac47e8163627f159f30d80d51b914620dd4"},{"type":"WEB","url":"https://git.kernel.org/stable/c/7b681dd5fbf60b24a13c14661e5b7735759fb491"},{"type":"WEB","url":"https://git.kernel.org/stable/c/89ff289cbf5d3b659a2babc5ccaae4eaf7e7cf53"},{"type":"WEB","url":"https://git.kernel.org/stable/c/c6d2af3b217a525741c472f0ab45d7d274b8468f"},{"type":"WEB","url":"https://git.kernel.org/stable/c/d638ec188e95fe60f4b01106ffd41958f8fb3c2c"},{"type":"WEB","url":"https://git.kernel.org/stable/c/f8163c414de8640f2ca82ce4dc93409d4cdc2fad"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64330.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64330"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"4ab8c18d4d67321cc7b660559de17511d4fc0237"},{"fixed":"89ff289cbf5d3b659a2babc5ccaae4eaf7e7cf53"},{"fixed":"d638ec188e95fe60f4b01106ffd41958f8fb3c2c"},{"fixed":"f8163c414de8640f2ca82ce4dc93409d4cdc2fad"},{"fixed":"012406f89abc52d1d5f07aa5653b519ebf6d2407"},{"fixed":"c6d2af3b217a525741c472f0ab45d7d274b8468f"},{"fixed":"3e1b1ac47e8163627f159f30d80d51b914620dd4"},{"fixed":"313ca06e7e224ca1dfadd5722fe71fb8bc276b8b"},{"fixed":"7b681dd5fbf60b24a13c14661e5b7735759fb491"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64330.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.19.0"},{"fixed":"5.10.261"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.212"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.178"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.145"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.96"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.39"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.1.4"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64330.json"}}],"schema_version":"1.7.5"}