Out-of-bounds write in Linux kernel - CVE-2026-63958
Published: July 20, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds write in ucsi_connector_change() when handling a crafted UCSI CCI notification with an invalid connector number. A local attacker can provide a bogus connector number to trigger work scheduling on memory past the end of the connector array to cause a denial of service.
Exploitation requires control of a buggy or malicious PPM, such as EC firmware or an attached UCSI controller on supported transports.
How to mitigate CVE-2026-63958
Sources
- https://git.kernel.org/stable/c/0edd1e21587b0483c7ceb993b9fb9668bbef7433
- https://git.kernel.org/stable/c/156b6f0aec6108909b0c4aedc78865b12766b347
- https://git.kernel.org/stable/c/288a81a8507052bcfbf884d39a463c44c42c5fd9
- https://git.kernel.org/stable/c/5af2719b460ab904c504fc069d1dd2a3aa2b22b0
- https://git.kernel.org/stable/c/bd24d92af4ae021b6209f28e9a57e1bf2260d4fd
- https://git.kernel.org/stable/c/cea949203faef9cb783adc7b978cce056271e057