usb: typec: ucsi: ccg: reject firmware images without a ':' record header
Summary
| CVE | CVE-2026-63964 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-07-19 16:17:15 UTC |
| Updated | 2026-07-20 07:16:41 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: ccg: reject firmware images without a ':' record header do_flash() locates the first .cyacd record with p = strnchr(fw->data, fw->size, ':'); while (p < eof) { s = strnchr(p + 1, eof - p - 1, ':'); ... } If the firmware image contains no ':' byte, strnchr() returns NULL. NULL compares less than the valid kernel pointer eof, so the loop body runs and strnchr() is called with p + 1 == (void *)1 and a length of roughly (unsigned long)eof, causing a wonderful crash. The not_signed_fw fallthrough earlier in do_flash() and the chip-state branches in ccg_fw_update_needed() allow an unsigned blob to reach this loop, so a root user who can place a crafted file under /lib/firmware and write the do_flash sysfs attribute can trigger the oops. Bail out with -EINVAL when the initial strnchr() returns NULL. |
Risk And Classification
EPSS: 0.002100000 probability, percentile 0.113690000 (date 2026-07-20)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 5c9ae5a87573d38cfc4c740aafda2fa6ce06e401 b41dfc033fe594e152648050e95b9489cd53e9e3 git | Not specified |
| CNA | Linux | Linux | affected 5c9ae5a87573d38cfc4c740aafda2fa6ce06e401 2f395ca1263bd181995eb829f5943a83a20db213 git | Not specified |
| CNA | Linux | Linux | affected 5c9ae5a87573d38cfc4c740aafda2fa6ce06e401 6526f8684f72391138353642af908803ba70795e git | Not specified |
| CNA | Linux | Linux | affected 5c9ae5a87573d38cfc4c740aafda2fa6ce06e401 3f432b8203066c26770fe6ea591361f10021dd6b git | Not specified |
| CNA | Linux | Linux | affected 5c9ae5a87573d38cfc4c740aafda2fa6ce06e401 c4ee519b06389e59ba2d6aa722fcc4a02a8bbcbb git | Not specified |
| CNA | Linux | Linux | affected 5c9ae5a87573d38cfc4c740aafda2fa6ce06e401 a38ed87818b2419090fb1a6338ddce6842b65dfa git | Not specified |
| CNA | Linux | Linux | affected 5c9ae5a87573d38cfc4c740aafda2fa6ce06e401 c8460de584fe5415d212cfdd127d4db90835a450 git | Not specified |
| CNA | Linux | Linux | affected 5c9ae5a87573d38cfc4c740aafda2fa6ce06e401 d7486952bf74e546ee3748fb14b2d07881fa6273 git | Not specified |
| CNA | Linux | Linux | affected 5.2 | Not specified |
| CNA | Linux | Linux | unaffected 5.2 semver | Not specified |
| CNA | Linux | Linux | unaffected 5.10.259 5.10.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.210 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.176 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.143 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.93 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.35 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.0.12 7.0.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.1 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/2f395ca1263bd181995eb829f5943a83a20db213 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/a38ed87818b2419090fb1a6338ddce6842b65dfa | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/b41dfc033fe594e152648050e95b9489cd53e9e3 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/c4ee519b06389e59ba2d6aa722fcc4a02a8bbcbb | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/3f432b8203066c26770fe6ea591361f10021dd6b | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/d7486952bf74e546ee3748fb14b2d07881fa6273 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/c8460de584fe5415d212cfdd127d4db90835a450 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/6526f8684f72391138353642af908803ba70795e | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.