Back to overview

CVE-2026-63959

Description
In the Linux kernel, the following vulnerability has been resolved: usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT A broken/malicious port can transmit a CRC-valid frame whose header advertises up to seven data objects but whose body carries fewer than that. Check for this, and rightfully reject the message, instead of reading from uninitialized stack memory.

Metadata

CVE ID
CVE-2026-63959
State
PUBLISHED
Assigner
Linux
Reserved
2026-07-19 07:54 UTC
Published
2026-07-19 14:55 UTC
Last updated
2026-07-20 06:41 UTC
Vendor / Product
Linux / Linux
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (2)
VendorProductPlatformVersions
Linux Linux 6f413b559f86a2894188e082e389ff95ee428345 < 0af00f1459f5dd757f0d392f8caa38039561ac62, 6f413b559f86a2894188e082e389ff95ee428345 < dc17721d42e6d89f63572e63add8306a0e15eb3c, 6f413b559f86a2894188e082e389ff95ee428345 < 9b496e3371c04f0a03b7faa5d2442536d00e3998, 6f413b559f86a2894188e082e389ff95ee428345 < c4ab8e2d4432abb646c5c0687f8dab173da901f9 …
Linux Linux 5.10, 0 < 5.10, 6.6.143 ≤ 6.6.*, 6.12.93 ≤ 6.12.* …
Back to overview