CVE-2026-63928

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/07/2026
Last modified:
27/07/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> USB: serial: omninet: fix memory corruption with small endpoint<br /> <br /> Make sure that the bulk-out buffers are at least as large as the<br /> hardcoded transfer size to avoid user-controlled slab corruption should<br /> a malicious device report a smaller endpoint max packet size than<br /> expected.

Impact