usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT
Summary
| CVE | CVE-2026-63959 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-07-19 16:17:14 UTC |
| Updated | 2026-07-20 07:16:41 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT A broken/malicious port can transmit a CRC-valid frame whose header advertises up to seven data objects but whose body carries fewer than that. Check for this, and rightfully reject the message, instead of reading from uninitialized stack memory. |
Risk And Classification
EPSS: 0.002000000 probability, percentile 0.100200000 (date 2026-07-20)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 6f413b559f86a2894188e082e389ff95ee428345 0af00f1459f5dd757f0d392f8caa38039561ac62 git | Not specified |
| CNA | Linux | Linux | affected 6f413b559f86a2894188e082e389ff95ee428345 dc17721d42e6d89f63572e63add8306a0e15eb3c git | Not specified |
| CNA | Linux | Linux | affected 6f413b559f86a2894188e082e389ff95ee428345 9b496e3371c04f0a03b7faa5d2442536d00e3998 git | Not specified |
| CNA | Linux | Linux | affected 6f413b559f86a2894188e082e389ff95ee428345 c4ab8e2d4432abb646c5c0687f8dab173da901f9 git | Not specified |
| CNA | Linux | Linux | affected 6f413b559f86a2894188e082e389ff95ee428345 aa2f716327be1818e1cb156da8a2844804aaec2f git | Not specified |
| CNA | Linux | Linux | affected 5.10 | Not specified |
| CNA | Linux | Linux | unaffected 5.10 semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.143 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.93 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.35 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.0.12 7.0.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.1 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/c4ab8e2d4432abb646c5c0687f8dab173da901f9 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/aa2f716327be1818e1cb156da8a2844804aaec2f | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/dc17721d42e6d89f63572e63add8306a0e15eb3c | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/9b496e3371c04f0a03b7faa5d2442536d00e3998 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/0af00f1459f5dd757f0d392f8caa38039561ac62 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.