Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-63898

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
19/07/2026
Última modificación:
19/07/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> USB: serial: mct_u232: fix memory corruption with small endpoint<br /> <br /> The driver overrides the maximum transfer size for a specific device<br /> which only accepts 16 byte packets for its 32 byte bulk-out endpoint.<br /> <br /> Make sure to never increase the maximum transfer size to prevent slab<br /> corruption should a malicious device report a smaller endpoint max<br /> packet size than expected.

Impacto