CVE-2026-63892
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/07/2026
Last modified:
19/07/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
thunderbolt: property: Reject dir_len length (u16 widened to size_t). Two distinct OOB conditions<br />
follow when entry->length uuid), ...) which always reads 4 dwords from<br />
dir_offset. tb_property_entry_valid() only enforces<br />
dir_offset + entry->length length in 0..3 passes that gate but lets the UUID copy<br />
run off the block (e.g. dir_offset = 497, dir_len = 3 in a<br />
500-dword block reads block[497..501]).<br />
<br />
2. After the kmemdup, content_len = dir_len - 4 underflows size_t<br />
to ~SIZE_MAX, nentries becomes SIZE_MAX / 4, and the entry<br />
walk runs OOB on each iteration until an entry fails<br />
validation or the kernel oopses on an unmapped page.<br />
<br />
Reject dir_len properties) up to immediately after<br />
the dir allocation so the new error-return path (and the existing<br />
uuid-alloc failure path) calling tb_property_free_dir() sees a<br />
walkable list rather than the zero-initialized NULL next/prev that<br />
list_for_each_entry_safe() would oops on.
Impact
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/37abc4504fa19d8f9f1e87792e8a2b8fdb308e40
- https://git.kernel.org/stable/c/3bec49ca55e08fb085cc4318f24b1b37eaab28cb
- https://git.kernel.org/stable/c/542a13890b742099c461d70920e97b14e568f6ec
- https://git.kernel.org/stable/c/5506c825f14d810f0690b1f4367cb7249ebb387a
- https://git.kernel.org/stable/c/d548179adcc87e1bc66b17e00352a1f536e76065
- https://git.kernel.org/stable/c/de21b59c29e31c5108ddc04210631bbfab81b997
- https://git.kernel.org/stable/c/de618299190b418291609e6921557253bd417e25
- https://git.kernel.org/stable/c/e2d4d51cf5785815fa4e91e0c019e3eb2506a84c



