Out-of-bounds read in Linux kernel - CVE-2026-63961
Published: July 20, 2026
Vulnerability details
The vulnerability allows an attacker with physical access to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in the DisplayPort altmode handler when processing a malformed Status Update VDO from a connected USB Type-C device. An attacker with physical access can send a device response with an incorrect VDO count to disclose sensitive information.
The issue can cause the kernel to read uninitialized stack data and forward it elsewhere.
Affected software
Ubuntu
linux-ibm (Ubuntu package)
linux-azure (Ubuntu package)
linux-aws (Ubuntu package)
linux-nvidia (Ubuntu package)
linux-nvidia-bos (Ubuntu package)
How to mitigate CVE-2026-63961
linux-ibm (Ubuntu package) - addressed in versions 7.0.0-1008.8, 7.0.0-1010.10
linux-azure (Ubuntu package) - addressed in versions 7.0.0-1009.9, 7.0.0-1010.10
linux-aws (Ubuntu package) - addressed in versions 7.0.0-1009.9, 7.0.0-1015.15
linux-nvidia (Ubuntu package) - addressed in versions 7.0.0-1016.16, 7.0.0-1016.16~24.04.1
linux-nvidia-bos (Ubuntu package) - update to 7.0.0-2016.16
External References
- https://git.kernel.org/stable/c/64bd6ccc5799f8473d1f37d4d8f53093dfec5c02
- https://git.kernel.org/stable/c/6ffdbcd7a02f3af8fff9b6519830369f574ed44c
- https://git.kernel.org/stable/c/70e7045849e954e56dcbf441b6330e66bc996306
- https://git.kernel.org/stable/c/74aabe9ea30fdfba924fce9594e6aa69a596a4bb
- https://git.kernel.org/stable/c/77a759ec30bc5fb0dd9c867b711d0acfed6c7faa
- https://git.kernel.org/stable/c/8a18f896e667df491331371b55d4ad644dc51d60
- https://git.kernel.org/stable/c/b10eff5abe6aa2a5af10ed17bddff76e3b6e6b9b
- https://git.kernel.org/stable/c/dd7118c010f324497c275e8fd7a35c9baaa2a00f