Back to overview

CVE-2026-63961

Description
In the Linux kernel, the following vulnerability has been resolved: usb: typec: altmodes/displayport: validate count before reading Status Update VDO A broken/malicious device can send the incorrect count for a status update VDO, which will cause the kernel to read uninitialized stack data and send it off elsewhere. Fix this up by correctly verifying the count for the update object.

Metadata

CVE ID
CVE-2026-63961
State
PUBLISHED
Assigner
Linux
Reserved
2026-07-19 07:54 UTC
Published
2026-07-19 14:55 UTC
Last updated
2026-07-20 06:41 UTC
Vendor / Product
Linux / Linux
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (2)
VendorProductPlatformVersions
Linux Linux 0e3bb7d6894d9b6e67d6382bb03a46a1dc989588 < 74aabe9ea30fdfba924fce9594e6aa69a596a4bb, 0e3bb7d6894d9b6e67d6382bb03a46a1dc989588 < dd7118c010f324497c275e8fd7a35c9baaa2a00f, 0e3bb7d6894d9b6e67d6382bb03a46a1dc989588 < 6ffdbcd7a02f3af8fff9b6519830369f574ed44c, 0e3bb7d6894d9b6e67d6382bb03a46a1dc989588 < 70e7045849e954e56dcbf441b6330e66bc996306 …
Linux Linux 4.19, 0 < 4.19, 5.10.259 ≤ 5.10.*, 5.15.210 ≤ 5.15.* …
Back to overview