SB20260720281 - Out-of-bounds write in Linux kernel typec tcpm driver
Published: July 20, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds write (CVE-ID: CVE-2026-63960)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows an attacker with physical access to cause memory corruption.
The vulnerability exists due to an out-of-bounds write in wcove_read_rx_buffer() when processing a crafted USB Power Delivery frame from a connected port partner. An attacker with physical access can transmit a crafted 31-byte frame to cause memory corruption.
The issue occurs on the IRQ thread stack, and the final register read may write past the end of struct pd_message.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/3e632098d0521257ea965bbd6fde807d9bee5c8a
- https://git.kernel.org/stable/c/3f9d50c8b02b4af0646aa892465080f9061fc89c
- https://git.kernel.org/stable/c/4af7ad0e6d7aa4403dbb1dac7b9659b0421efcaa
- https://git.kernel.org/stable/c/5cd0e7ac4eefbdb330f8c72694fe74e63df65552
- https://git.kernel.org/stable/c/6899f5b6d7b83ce79a3d331dc61dd31bf73f9c22
- https://git.kernel.org/stable/c/d0e4b8b3c6b7607a16932556eaaca5d5cf69f192
- https://git.kernel.org/stable/c/e94933dc41b87503bf585c8c6d53d740620eceb9
- https://git.kernel.org/stable/c/f2a1edc0bd142edabc6c85d88713f2bc178dd317