Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-63891

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
19/07/2026
Última modificación:
19/07/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> thunderbolt: property: Cap recursion depth in __tb_property_parse_dir()<br /> <br /> A DIRECTORY entry&amp;#39;s value field is used as the dir_offset for a<br /> recursive call into __tb_property_parse_dir() with no depth counter.<br /> A crafted peer that chains DIRECTORY entries into a back-reference<br /> loop drives the parser until the kernel stack is exhausted and the<br /> guard page fires. Any untrusted XDomain peer (cable, dock, in-line<br /> inspector, adjacent host) that reaches the PROPERTIES_REQUEST<br /> control-plane exchange can trigger this without authentication.<br /> <br /> Thread a depth counter through tb_property_parse() and<br /> __tb_property_parse_dir(), and reject blocks that exceed<br /> TB_PROPERTY_MAX_DEPTH = 8. That is comfortably larger than any<br /> observed legitimate XDomain layout.<br /> <br /> Operators who do not need XDomain host-to-host discovery can disable<br /> the path entirely with thunderbolt.xdomain=0 on the kernel command<br /> line.

Impacto