Repository navigation
This release fixes three out-of-bounds reads in the host classes, each of them reached by a device reporting a length larger than the buffer the host sized for it. Four APIs are flagged as deprecated.
We thank contributors from Causal Security and STMicroelectronics, along with the independent contributors @acorn421, @adawn0106 and @Microsvuln, for their valuable contributions to this release.
The USBX user guide is attached to this release as a PDF, in A4 and US Letter.
Vulnerabilities addressed
Three vulnerabilities are fixed in 6.5.2.202603. All three share a shape: a value taken from the device is used as a bound without being checked against the buffer that actually holds the data, so a malicious or malfunctioning peripheral reads host memory past the end of a descriptor or response. Attaching the device is the whole of the attack.
- CVE-2026-96402 (4.9 Medium, CWE-125)
PIMA/MTP host class reads past its receive buffer when a device over-reports its object handle count - CVE-2026-96406 (4.9 Medium, CWE-125)
VIDEO class descriptor walk consumes device-controlled wTotalLength as its bound - CVE-2026-96582 (4.9 Medium, CWE-125, CWE-1285)
Out-of-bounds read via check-after-use in the HID report descriptor parser
All three affect every release up to and including 6.5.1.202602, and all are fixed in 6.5.2.202603.
The PIMA defect was reported by @Microsvuln, the VIDEO one by @cipher-creator of Causal Security, and the HID one by @cipher-creator, @acorn421, @adawn0106 and @rahmanih.
Each advisory ships regression tests that fail when its fix is reverted. One exception is recorded in the source: the bound in _ux_host_class_video_activate is the same condition as the one covered in _ux_host_class_video_input_format_get, and the status it propagates comes from _ux_host_class_video_entities_parse, which is also covered; the call site composing the two is not separately tested, because reaching it needs a simulated host and device stack.
You can access advisories for previously addressed vulnerabilities here.
Highlights
The host classes no longer trust a device's own lengths
The three defects are the same mistake in three places. A PIMA device reports how many object handles follow; the host sized a buffer for a maximum and then read the reported count out of it. A VIDEO device reports wTotalLength for its format block; the host walked that far regardless of how much configuration descriptor remained. A HID device declares the size of each report item's data; the parser advanced first and checked afterwards.
In each case the fix is the same: bound the walk by the buffer the host allocated rather than by the number the device supplied, and refuse the descriptor when the two disagree. The VIDEO fix also stops a corrupted-descriptor result from being reported to the caller as a successful parse.
Deprecations
Four USBX APIs are flagged as deprecated. (#269, @fdesbiens)
Other Changes
- Removed a stray byte order mark that broke the regression build (#274, @fdesbiens)
- Updated the security policy (#270, @fdesbiens)
- Stopped the release script adding a
Co-authored-bytrailer, which asserts an authorship an AI cannot hold (#282, @fdesbiens)
Full Changelog: v6.5.1.202602_rel...v6.5.2.202603_rel