thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow

Summary

CVECVE-2026-63892
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-07-19 16:17:06 UTC
Updated2026-07-19 16:17:06 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow On the non-root path, __tb_property_parse_dir() takes dir_len from entry->length (u16 widened to size_t). Two distinct OOB conditions follow when entry->length < 4: 1. The non-root path begins with kmemdup(&block[dir_offset], sizeof(*dir->uuid), ...) which always reads 4 dwords from dir_offset. tb_property_entry_valid() only enforces dir_offset + entry->length <= block_len, so a crafted entry with dir_offset close to the end of the property block and entry->length in 0..3 passes that gate but lets the UUID copy run off the block (e.g. dir_offset = 497, dir_len = 3 in a 500-dword block reads block[497..501]). 2. After the kmemdup, content_len = dir_len - 4 underflows size_t to ~SIZE_MAX, nentries becomes SIZE_MAX / 4, and the entry walk runs OOB on each iteration until an entry fails validation or the kernel oopses on an unmapped page. Reject dir_len < 4 on the non-root path *before* the UUID kmemdup, which closes both holes. Also move INIT_LIST_HEAD(&dir->properties) up to immediately after the dir allocation so the new error-return path (and the existing uuid-alloc failure path) calling tb_property_free_dir() sees a walkable list rather than the zero-initialized NULL next/prev that list_for_each_entry_safe() would oops on.

Risk And Classification

EPSS: 0.002200000 probability, percentile 0.125290000 (date 2026-07-20)

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected cdae7c07e3e3509eaabc18c1640a55dc5b99c179 37abc4504fa19d8f9f1e87792e8a2b8fdb308e40 git Not specified
CNA Linux Linux affected cdae7c07e3e3509eaabc18c1640a55dc5b99c179 e2d4d51cf5785815fa4e91e0c019e3eb2506a84c git Not specified
CNA Linux Linux affected cdae7c07e3e3509eaabc18c1640a55dc5b99c179 de618299190b418291609e6921557253bd417e25 git Not specified
CNA Linux Linux affected cdae7c07e3e3509eaabc18c1640a55dc5b99c179 5506c825f14d810f0690b1f4367cb7249ebb387a git Not specified
CNA Linux Linux affected cdae7c07e3e3509eaabc18c1640a55dc5b99c179 542a13890b742099c461d70920e97b14e568f6ec git Not specified
CNA Linux Linux affected cdae7c07e3e3509eaabc18c1640a55dc5b99c179 d548179adcc87e1bc66b17e00352a1f536e76065 git Not specified
CNA Linux Linux affected cdae7c07e3e3509eaabc18c1640a55dc5b99c179 3bec49ca55e08fb085cc4318f24b1b37eaab28cb git Not specified
CNA Linux Linux affected cdae7c07e3e3509eaabc18c1640a55dc5b99c179 de21b59c29e31c5108ddc04210631bbfab81b997 git Not specified
CNA Linux Linux affected 4.15 Not specified
CNA Linux Linux unaffected 4.15 semver Not specified
CNA Linux Linux unaffected 5.10.259 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.210 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.176 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.143 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.93 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.35 6.18.* semver Not specified
CNA Linux Linux unaffected 7.0.12 7.0.* semver Not specified
CNA Linux Linux unaffected 7.1 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/37abc4504fa19d8f9f1e87792e8a2b8fdb308e40 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/e2d4d51cf5785815fa4e91e0c019e3eb2506a84c 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/5506c825f14d810f0690b1f4367cb7249ebb387a 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/de618299190b418291609e6921557253bd417e25 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/3bec49ca55e08fb085cc4318f24b1b37eaab28cb 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/d548179adcc87e1bc66b17e00352a1f536e76065 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/542a13890b742099c461d70920e97b14e568f6ec 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/de21b59c29e31c5108ddc04210631bbfab81b997 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report