CVE-2026-89621
Received Received - Intake

Buffer Overflow in Linux Kernel HID MCP2221 Driver

Vulnerability report for CVE-2026-89621, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-14

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: HID: mcp2221: validate report size in mcp2221_raw_event() mcp2221_raw_event() never validates the size of incoming HID reports. In the MCP2221_I2C_GET_DATA path it trusts the device-supplied data[3] as the copy length without checking that 4 + data[3] bytes actually exist in the received report. A malicious or misbehaving USB device can send a short report with a large data[3], causing the memcpy to read past the valid report data in the HID transfer buffer and leak uninitialized kernel memory back to userspace through the I2C/SMBus read path. Add a minimum size check at entry and validate that the source range fits within the received report before the copy.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-14
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the Linux kernel's HID driver for the MCP2221 USB device. The function mcp2221_raw_event() fails to validate the size of incoming HID reports. When processing I2C data, it uses a device-supplied value to determine copy length without checking if the report contains enough data. This can cause a buffer over-read, leaking uninitialized kernel memory to userspace.

Detection Guidance

This vulnerability involves a memory leak in the Linux kernel's HID subsystem for MCP2221 devices. Detection requires checking kernel logs for related errors or unusual memory access patterns. Monitor dmesg or syslog for HID-related warnings. No specific commands are provided in the context to directly detect this issue.

Impact Analysis

An attacker with physical or USB access could exploit this to read sensitive kernel memory. This might expose passwords, encryption keys, or other confidential data. It could also crash the system or enable further attacks by providing crafted data.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards as it involves a memory leak in the Linux kernel's HID subsystem. However, if exploited, it could potentially lead to unauthorized data exposure, which may indirectly impact compliance by violating data protection principles.

Mitigation Strategies

Apply the latest Linux kernel updates to patch this vulnerability. If immediate patching is not possible, consider disabling the MCP2221 HID driver module temporarily. Avoid using untrusted USB devices with I2C/SMBus functionality until the system is updated.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89621. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart