CVE-2026-63959
In the Linux kernel, the following vulnerability has been resolved: usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT A broken/malicious port can transmit a CRC-valid frame whose header advertises up to seven data objects but whose…
Does this matter?
Not yet scored. NVD analysis is pending; check back once CVSS and EPSS values are published.
Description
In the Linux kernel, the following vulnerability has been resolved: usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT A broken/malicious port can transmit a CRC-valid frame whose header advertises up to seven data objects but whose body carries fewer than that. Check for this, and rightfully reject the message, instead of reading from uninitialized stack memory.
- CVSS
- Not yet scored
- EPSS
- 0.21% probability · 11th percentile
- CISA KEV
- Not listed
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/0af00f1459f5dd757f0d392f8caa38039561ac62
- https://git.kernel.org/stable/c/9b496e3371c04f0a03b7faa5d2442536d00e3998
- https://git.kernel.org/stable/c/aa2f716327be1818e1cb156da8a2844804aaec2f
- https://git.kernel.org/stable/c/c4ab8e2d4432abb646c5c0687f8dab173da901f9
- https://git.kernel.org/stable/c/dc17721d42e6d89f63572e63add8306a0e15eb3c
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.