Out-of-bounds read in Linux kernel - CVE-2026-63904
Published: July 20, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in the usbtmc interrupt notification handling in drivers/usb/class/usbtmc.c when processing interrupt-in notifications with an insufficient URB actual_length. A local attacker can provide a crafted USBTMC device that sends a short notification to disclose sensitive information.
The issue can also cause stale leftover data from a previous notification to be consumed.
How to mitigate CVE-2026-63904
Sources
- https://git.kernel.org/stable/c/52f2ad3f7e5eb3b5908e1d685d4342519dc9cfcd
- https://git.kernel.org/stable/c/5de7df75ef3a2756b25fe3d582a4a2970444fe5a
- https://git.kernel.org/stable/c/69020fa089f1bf0e1a10a15265f31b143a846409
- https://git.kernel.org/stable/c/75f6d3da2cc646983f41807ef98851569c12bca9
- https://git.kernel.org/stable/c/ae87f505917e703ae3b487d9663d78826ff43608
- https://git.kernel.org/stable/c/e3eec3005de44e7f37d8d7724be636446516ab42
- https://git.kernel.org/stable/c/e794bd67b3faf98af46f958897f6b91412c7d2a9
- https://git.kernel.org/stable/c/f141b01eaa58ac7e323931d670318aa247bff087