CVE-2026-63959
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/07/2026
Last modified:
20/07/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT<br />
<br />
A broken/malicious port can transmit a CRC-valid frame whose header<br />
advertises up to seven data objects but whose body carries fewer than<br />
that. Check for this, and rightfully reject the message, instead of<br />
reading from uninitialized stack memory.
Impact
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/0af00f1459f5dd757f0d392f8caa38039561ac62
- https://git.kernel.org/stable/c/9b496e3371c04f0a03b7faa5d2442536d00e3998
- https://git.kernel.org/stable/c/aa2f716327be1818e1cb156da8a2844804aaec2f
- https://git.kernel.org/stable/c/c4ab8e2d4432abb646c5c0687f8dab173da901f9
- https://git.kernel.org/stable/c/dc17721d42e6d89f63572e63add8306a0e15eb3c



