Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-64336
Linux Linux — USB: serial: keyspan_pda: fix information leak
AV AC PR UI S C I A CVSS EPSS %ile KEV
L L L N U N N H 5.5 .0012 1.8 —
AFFECTED
Product Versions Fixed
Linux 034e38e8f68767fb5438ae3e608ee82919674177 – —
Linux 5.11 – 5.15.212
TIMELINE
Jul 19 Reserved by Linux
Jul 25 Published (CNA: Linux)
Sep 3 ENRICHED — CVE-2026-64336 (Linux). Received CVSS 5.5 and CPE data from NVD.
Description
In the Linux kernel, the following vulnerability has been resolved:
USB: serial: keyspan_pda: fix information leak
The write() callback is supposed to return the number of characters
accepted or a negative errno. Since the addition of write fifo support
the keyspan_pda implementation will however return the number characters
submitted to the device if the write urb is not already in use. If this
number is larger than the number of characters passed to write(), the
line discipline continues writing data from beyond the tty write buffer.
Fix the information leak by making sure that keyspan_pda_write_start()
returns zero on success as intended.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| July 19, 2026 | Reserved | Reserved by Linux |
| July 25, 2026 | Published | Published (CNA: Linux) |
| September 3, 2026 | ENRICHED | ENRICHED — CVE-2026-64336 (Linux). Received CVSS 5.5 and CPE data from NVD. |
Affected
Affected products and packages — 2 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Linux | Linux | — | 034e38e8f68767fb5438ae3e608ee82919674177 | — |
| Linux | Linux | — | 5.11 | 5.15.212 |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-64336 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.