Out-of-bounds read in Linux kernel - CVE-2026-63961
Published: July 20, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows an attacker with physical access to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in the DisplayPort altmode handler when processing a malformed Status Update VDO from a connected USB Type-C device. An attacker with physical access can send a device response with an incorrect VDO count to disclose sensitive information.
The issue can cause the kernel to read uninitialized stack data and forward it elsewhere.
How to mitigate CVE-2026-63961
Sources
- https://git.kernel.org/stable/c/64bd6ccc5799f8473d1f37d4d8f53093dfec5c02
- https://git.kernel.org/stable/c/6ffdbcd7a02f3af8fff9b6519830369f574ed44c
- https://git.kernel.org/stable/c/70e7045849e954e56dcbf441b6330e66bc996306
- https://git.kernel.org/stable/c/74aabe9ea30fdfba924fce9594e6aa69a596a4bb
- https://git.kernel.org/stable/c/77a759ec30bc5fb0dd9c867b711d0acfed6c7faa
- https://git.kernel.org/stable/c/8a18f896e667df491331371b55d4ad644dc51d60
- https://git.kernel.org/stable/c/b10eff5abe6aa2a5af10ed17bddff76e3b6e6b9b
- https://git.kernel.org/stable/c/dd7118c010f324497c275e8fd7a35c9baaa2a00f