Driver hang via zero-length USB descriptor
Published Aug 28, 2026 · Updated Aug 28, 2026
Infinite-loop denial of service in the ims-pcu driver in Linux allows physically proximate attackers to hang the driver via a USB device. The ims_pcu_get_cdc_union_desc() parser advances by each descriptor's bLength without rejecting values below 2, so a zero value prevents progress. Exploitation requires attaching a malicious USB device exposing the ims-pcu interface; the loop interrupts descriptor parsing and consumes the executing context indefinitely.
Summary
What happened
Infinite-loop denial of service in the ims-pcu driver in Linux allows physically proximate attackers to hang the driver via a USB device. The ims_pcu_get_cdc_union_desc() parser advances by each descriptor's bLength without rejecting values below 2, so a zero value prevents progress. Exploitation requires attaching a malicious USB device exposing the ims-pcu interface; the loop interrupts descriptor parsing and consumes the executing context indefinitely.
The record
- CVE
- CVE-2026-80594
- Published
- Aug 28, 2026
- Updated
- Aug 28, 2026
- Vendor
- The Linux Kernel Organization
- Product
- Linux
- Classifications
- T1499.004
- Attack vector
- physical
- Privileges
- unauthenticated
Timeline
How it unfolded
- Aug 28, 2026CVE publishedPublication date reported by the CVE source.
- Aug 28, 2026Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=3.10
- Affected versionversion=628329d52474323938a03826941e166bc7c8eff4 <383934c249a9817d242d02d30bfbc8defbf0d533
- Affected versionversion=628329d52474323938a03826941e166bc7c8eff4 <6314bd9e2a6b3362998dc85485dd4b0f133a3532
- Affected versionversion=628329d52474323938a03826941e166bc7c8eff4 <67a038c5a7c9bd8aabe6fba8ac9d2e31c0bd5a28
- Affected versionversion=628329d52474323938a03826941e166bc7c8eff4 <76eeeb3a8e3c13d5c0ef28666b57dcb5cc101a32
- Affected versionversion=628329d52474323938a03826941e166bc7c8eff4 <b847f2725ef47a26b3d01eca3d54fd811e5a544d
- Affected versionversion=628329d52474323938a03826941e166bc7c8eff4 <bbbe31486cf2d12177462e4a814244c2597c9849
- Affected versionversion=628329d52474323938a03826941e166bc7c8eff4 <d4579af29e67ca8722db0a1194227f8015c8981d
- Affected versionversion=628329d52474323938a03826941e166bc7c8eff4 <e3f93d63dcd48c1f0ba9041f2ffa8aea7170e295
What conditions does exploitation require?
What is affected?
Published CVSS scores
No CVSS assessment is available in this record.
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
No public exploit references are available in this record.
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo