Out-of-bounds read in Linux kernel - CVE-2026-63943
Published: July 20, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows an attacker with physical access to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in xpadone_process_packet() when processing a crafted GIP_CMD_INPUT packet from a device. An attacker with physical access can supply a malformed controller packet with a short length to cause a denial of service.
The issue is triggered by a broken or malicious controller that controls both the reported packet length and packet contents.
How to mitigate CVE-2026-63943
Sources
- https://git.kernel.org/stable/c/37ec54abfdd63a63fd50734a9c4e4cbc1e5795af
- https://git.kernel.org/stable/c/6346b0895b574ce45f3747b9c508c72f70e6abef
- https://git.kernel.org/stable/c/6cdc46b38cf146ce81d4831b6472dbf7731849a2
- https://git.kernel.org/stable/c/9749db57233b396353ad5dee81eec9d9880c9246
- https://git.kernel.org/stable/c/bcfb4833cd4078a1a356ef451838b75cd233099e