Out-of-bounds read in Linux kernel - CVE-2026-63959
Published: July 20, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows an attacker with physical access to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in the tcpci_maxim RX message processing logic when processing a crafted USB Type-C/Power Delivery frame with a mismatched header data object count. An attacker with physical access can send a specially crafted frame to disclose sensitive information.
The issue occurs when a CRC-valid frame advertises more data objects in the header than are actually present in the message body.
How to mitigate CVE-2026-63959
Sources
- https://git.kernel.org/stable/c/0af00f1459f5dd757f0d392f8caa38039561ac62
- https://git.kernel.org/stable/c/9b496e3371c04f0a03b7faa5d2442536d00e3998
- https://git.kernel.org/stable/c/aa2f716327be1818e1cb156da8a2844804aaec2f
- https://git.kernel.org/stable/c/c4ab8e2d4432abb646c5c0687f8dab173da901f9
- https://git.kernel.org/stable/c/dc17721d42e6d89f63572e63add8306a0e15eb3c