Out-of-bounds write in Linux kernel - CVE-2026-63958
Published: July 20, 2026
Vulnerability details
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds write in ucsi_connector_change() when handling a crafted UCSI CCI notification with an invalid connector number. A local attacker can provide a bogus connector number to trigger work scheduling on memory past the end of the connector array to cause a denial of service.
Exploitation requires control of a buggy or malicious PPM, such as EC firmware or an attached UCSI controller on supported transports.
Affected software
Ubuntu
linux-ibm (Ubuntu package)
linux-azure (Ubuntu package)
linux-aws (Ubuntu package)
linux-nvidia (Ubuntu package)
linux-nvidia-bos (Ubuntu package)
How to mitigate CVE-2026-63958
linux-ibm (Ubuntu package) - addressed in versions 7.0.0-1008.8, 7.0.0-1010.10
linux-azure (Ubuntu package) - addressed in versions 7.0.0-1009.9, 7.0.0-1010.10
linux-aws (Ubuntu package) - addressed in versions 7.0.0-1009.9, 7.0.0-1015.15
linux-nvidia (Ubuntu package) - addressed in versions 7.0.0-1016.16, 7.0.0-1016.16~24.04.1
linux-nvidia-bos (Ubuntu package) - update to 7.0.0-2016.16
External References
- https://git.kernel.org/stable/c/0edd1e21587b0483c7ceb993b9fb9668bbef7433
- https://git.kernel.org/stable/c/156b6f0aec6108909b0c4aedc78865b12766b347
- https://git.kernel.org/stable/c/288a81a8507052bcfbf884d39a463c44c42c5fd9
- https://git.kernel.org/stable/c/5af2719b460ab904c504fc069d1dd2a3aa2b22b0
- https://git.kernel.org/stable/c/bd24d92af4ae021b6209f28e9a57e1bf2260d4fd
- https://git.kernel.org/stable/c/cea949203faef9cb783adc7b978cce056271e057