Out-of-bounds write in Linux kernel - CVE-2026-63928
Published: July 20, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows an attacker with physical access to cause memory corruption.
The vulnerability exists due to memory corruption in the omninet USB serial driver bulk-out buffer handling when processing a malicious USB device that reports a smaller endpoint max packet size than expected. An attacker with physical access can connect a crafted USB device to cause memory corruption.
The issue can lead to user-controlled slab corruption.
How to mitigate CVE-2026-63928
Sources
- https://git.kernel.org/stable/c/0bda1893e4cc4ad2b7dcdbaca246f2af688c6c2a
- https://git.kernel.org/stable/c/0fee0ccac29e088d4bfab7e2d075725dcecd803d
- https://git.kernel.org/stable/c/180996f0ca774001944e4afa452d569ba2f6455c
- https://git.kernel.org/stable/c/4e7d32189d6219beb7db37cd0ea36b6bac7dfedb
- https://git.kernel.org/stable/c/60df93d30f9bdd27db17c4d80ed80ef718d7226b
- https://git.kernel.org/stable/c/9a3860454bdfb765f936965e975c594352602ffc
- https://git.kernel.org/stable/c/b496e25ead5976bce2891dacaed09beb53a54f9f
- https://git.kernel.org/stable/c/f34cf2928387fba01a78381f3258c7e1428897d9