CVE-2026-63956

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/07/2026
Last modified:
19/07/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> USB: serial: cypress_m8: fix memory corruption with small endpoint<br /> <br /> Make sure that the interrupt-out endpoint max packet size is at least<br /> eight bytes to avoid user-controlled slab corruption or NULL-pointer<br /> dereference should a malicious device report a smaller size.

Impact