Out-of-bounds write in Linux kernel - CVE-2026-63928

 

Out-of-bounds write in Linux kernel - CVE-2026-63928

Published: July 20, 2026


Vulnerability identifier: #VU138716
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-63928
CWE-ID: CWE-787
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker with physical access to cause memory corruption.

The vulnerability exists due to memory corruption in the omninet USB serial driver bulk-out buffer handling when processing a malicious USB device that reports a smaller endpoint max packet size than expected. An attacker with physical access can connect a crafted USB device to cause memory corruption.

The issue can lead to user-controlled slab corruption.


Affected software

Linux kernel
openEuler
Ubuntu
python3-perf-debuginfo
kernel
bpftool
bpftool-debuginfo
kernel-debuginfo
kernel-debugsource
kernel-devel
kernel-source
kernel-tools
kernel-tools-debuginfo
kernel-tools-devel
perf
perf-debuginfo
python2-perf
python2-perf-debuginfo
python3-perf
kernel-headers
kernel-extra-modules
linux-ibm (Ubuntu package)
linux-aws (Ubuntu package)
linux-azure (Ubuntu package)
linux-nvidia (Ubuntu package)
linux-nvidia-bos (Ubuntu package)

How to mitigate CVE-2026-63928

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
python3-perf-debuginfo - addressed in versions 4.19.90-2607.4.0.0382, 5.10.0-326.0.0.227, 6.6.0-145.3.29.160
kernel - addressed in versions 4.19.90-2607.4.0.0382, 5.10.0-326.0.0.227, 6.6.0-145.3.29.160
bpftool - addressed in versions 4.19.90-2607.4.0.0382, 5.10.0-326.0.0.227, 6.6.0-145.3.29.160
bpftool-debuginfo - addressed in versions 4.19.90-2607.4.0.0382, 5.10.0-326.0.0.227, 6.6.0-145.3.29.160
kernel-debuginfo - addressed in versions 4.19.90-2607.4.0.0382, 5.10.0-326.0.0.227, 6.6.0-145.3.29.160
kernel-debugsource - addressed in versions 4.19.90-2607.4.0.0382, 5.10.0-326.0.0.227, 6.6.0-145.3.29.160
kernel-devel - addressed in versions 4.19.90-2607.4.0.0382, 5.10.0-326.0.0.227, 6.6.0-145.3.29.160
kernel-source - addressed in versions 4.19.90-2607.4.0.0382, 5.10.0-326.0.0.227, 6.6.0-145.3.29.160
kernel-tools - addressed in versions 4.19.90-2607.4.0.0382, 5.10.0-326.0.0.227, 6.6.0-145.3.29.160
kernel-tools-debuginfo - addressed in versions 4.19.90-2607.4.0.0382, 5.10.0-326.0.0.227, 6.6.0-145.3.29.160
kernel-tools-devel - addressed in versions 4.19.90-2607.4.0.0382, 5.10.0-326.0.0.227, 6.6.0-145.3.29.160
perf - addressed in versions 4.19.90-2607.4.0.0382, 5.10.0-326.0.0.227, 6.6.0-145.3.29.160
perf-debuginfo - addressed in versions 4.19.90-2607.4.0.0382, 5.10.0-326.0.0.227, 6.6.0-145.3.29.160
python2-perf - update to 4.19.90-2607.4.0.0382
python2-perf-debuginfo - update to 4.19.90-2607.4.0.0382
python3-perf - addressed in versions 4.19.90-2607.4.0.0382, 5.10.0-326.0.0.227, 6.6.0-145.3.29.160
kernel-headers - addressed in versions 5.10.0-326.0.0.227, 6.6.0-145.3.29.160
kernel-extra-modules - update to 6.6.0-145.3.29.160
linux-ibm (Ubuntu package) - addressed in versions 7.0.0-1008.8, 7.0.0-1010.10
linux-aws (Ubuntu package) - addressed in versions 7.0.0-1009.9, 7.0.0-1015.15
linux-azure (Ubuntu package) - addressed in versions 7.0.0-1009.9, 7.0.0-1010.10
linux-nvidia (Ubuntu package) - addressed in versions 7.0.0-1016.16, 7.0.0-1016.16~24.04.1
linux-nvidia-bos (Ubuntu package) - update to 7.0.0-2016.16

External References

Related Security Bulletins