Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: usb: core: config: Prevent OOB read in SS endpoint companion parsing usb_parse_ss_endpoint_companion() checks descriptor type before length, enabling a potentially odd read outside of the buffer size. Fix this up by checking the size first before looking at any of the fields in the descriptor.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 2.6.35, < 5.10.241 |
| Debian | Debian Linux | 11.0 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/058ad2b722812708fe90567875704ae36563e33bPatch
- https://git.kernel.org/stable/c/4fe6f472f0beef4281e6f03bc38a910a33be663fPatch
- https://git.kernel.org/stable/c/5badd56c711e2c8371d1670f9bd486697575423cPatch
- https://git.kernel.org/stable/c/5c3097ede7835d3caf6543eb70ff689af4550cd2Patch
- https://git.kernel.org/stable/c/9512510cee7d1becdb0e9413fdd3ab783e4e30eePatch
- https://git.kernel.org/stable/c/9843bcb187cb933861f7805022e6873905f669e4Patch
- https://git.kernel.org/stable/c/b10e0f868067c6f25bbfabdcf3e1e6432c24ca55Patch
- https://git.kernel.org/stable/c/cf16f408364efd8a68f39011a3b073c83a03612dPatch
- https://lists.debian.org/debian-lts-announce/2025/10/msg00007.htmlThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.htmlThird Party Advisory
- https://cert-portal.siemens.com/productcert/html/ssa-032379.html
FAQ
What is CVE-2025-39760?
CVE-2025-39760 is a vulnerability with a CVSS score of 7.1 (HIGH). In the Linux kernel, the following vulnerability has been resolved: usb: core: config: Prevent OOB read in SS endpoint companion parsing usb_parse_ss_endpoint_companion() checks descriptor type befo...
How severe is CVE-2025-39760?
CVE-2025-39760 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-39760?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Debian Debian Linux.