Linux kernel patch proposes detecting malicious USB devices

A developer has submitted a patch to the Linux kernel mailing list for a new driver that monitors USB keyboard-like devices for suspicious activity. The hid-omg-detect module scores devices based on typing patterns and other signals without interfering with normal input. If a device appears malicious, it issues a warning recommending the use of USBGuard for blocking.

Zubeyr Almaho proposed the hid-omg-detect driver, which passively observes Human Interface Device (HID) inputs from USB devices resembling keyboards. Submitted as the second revision, the patch addresses prior feedback on state management and logging practices from the initial version. Kernel maintainers will decide if it gets merged into the Linux kernel codebase, according to the proposal on the mailing list, as covered by Phoronix. The driver evaluates devices using three key metrics: keystroke timing entropy, the delay between plugging in and starting to type, and fingerprinting of USB descriptors. Legitimate human typing differs markedly from automated keystroke injection by malicious hardware. Upon exceeding a configurable score threshold, the module logs a kernel warning and suggests employing the userspace tool USBGuard for enforcement, without altering or delaying any input events. The patch targets threats like BadUSB, disclosed in 2014, where USB devices reprogram their firmware to mimic keyboards and execute payloads such as opening terminals or downloading malware. Another example is the O.MG Cable, which conceals a implant in a standard-looking USB cable to inject keystrokes, log data, spoof identifiers, and enable remote WiFi control. Proponents note that these attacks persist and evolve despite reduced media attention.

Makala yanayohusiana

Linux stable kernel maintainer Greg Kroah-Hartman has started using an AI-assisted fuzzing tool in a branch named 'clanker' to test the kernel codebase. The tool has already prompted fixes for vulnerabilities in subsystems like ksmbd and SMB. Patches from this effort now cover areas including USB, HID, WiFi, and networking.

Imeripotiwa na AI

The Linux kernel project has officially documented its policy on AI-assisted code contributions with the release of Linux 7.0. The guidelines require human accountability, disclosure of AI tool use, and a new 'Assisted-by' tag for patches involving AI. Sasha Levin formalized the consensus reached at the 2025 Maintainers Summit.

Linus Torvalds has announced the latest Linux release candidate while calling attention to a growing issue with AI-generated bug reports. The flood of such reports has rendered the kernel security mailing list nearly impossible to manage.

Imeripotiwa na AI

A security researcher has disclosed Dirty Frag, a new Linux kernel exploit that allows local users to gain root privileges. The flaw affects major distributions and remains unpatched on most systems despite earlier fixes for a similar issue.

Jumamosi, 23. Mwezi wa tano 2026, 01:36:41

Linux kernel flaw lets unprivileged users gain root access

Alhamisi, 21. Mwezi wa tano 2026, 05:10:13

Rust proposal targets 80 percent of linux kernel cves

Jumamosi, 16. Mwezi wa tano 2026, 01:18:29

Linux 7.1 kernel adds rules for security bugs and ai reports

Jumatatu, 11. Mwezi wa tano 2026, 16:32:24

Linux kernel could gain kill switch for vulnerable functions

Ijumaa, 3. Mwezi wa nne 2026, 10:14:58

OpenClaw patches severe vulnerability granting admin access

Jumanne, 24. Mwezi wa tatu 2026, 02:32:57

Linux kernel project tests AI tool Sashiko for patch reviews

Tovuti hii inatumia vidakuzi

Tunatumia vidakuzi kwa uchambuzi ili kuboresha tovuti yetu. Soma sera ya faragha yetu kwa maelezo zaidi.
Kataa