Out-of-bounds write in Linux kernel - CVE-2026-63995
Published: July 20, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows an attacker with physical access to cause memory corruption.
The vulnerability exists due to an out-of-bounds write in cmis_fw_update_start_download() when processing a CMIS module firmware management features reply. An attacker with physical access can provide a malicious module response with an oversized start command payload value to cause memory corruption.
A malicious module or a corrupted response can trigger the issue during CMIS firmware update handling.