CVE-2026-63892

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/07/2026
Last modified:
19/07/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> thunderbolt: property: Reject dir_len length (u16 widened to size_t). Two distinct OOB conditions<br /> follow when entry-&gt;length uuid), ...) which always reads 4 dwords from<br /> dir_offset. tb_property_entry_valid() only enforces<br /> dir_offset + entry-&gt;length length in 0..3 passes that gate but lets the UUID copy<br /> run off the block (e.g. dir_offset = 497, dir_len = 3 in a<br /> 500-dword block reads block[497..501]).<br /> <br /> 2. After the kmemdup, content_len = dir_len - 4 underflows size_t<br /> to ~SIZE_MAX, nentries becomes SIZE_MAX / 4, and the entry<br /> walk runs OOB on each iteration until an entry fails<br /> validation or the kernel oopses on an unmapped page.<br /> <br /> Reject dir_len properties) up to immediately after<br /> the dir allocation so the new error-return path (and the existing<br /> uuid-alloc failure path) calling tb_property_free_dir() sees a<br /> walkable list rather than the zero-initialized NULL next/prev that<br /> list_for_each_entry_safe() would oops on.

Impact