PT-2026-61275 · Linux · Linux

CVE-2026-63958

·

Publicado

2026-07-19

·

Atualizado

2026-07-19

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
usb: typec: ucsi: validate connector number in ucsi connector change()
The connector number in a UCSI CCI notification is a 7-bit field supplied by the PPM. ucsi connector change() uses it to index the ucsi->connector[] array without checking it against the number of connectors the PPM reported at init time, so a buggy or malicious PPM (EC firmware, or an I2C-attached UCSI controller on the ccg / stm32g0 / glink transports) can drive schedule work() on memory past the end of the array.
Reject connector numbers that are zero or exceed cap.num connectors before dereferencing the array.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-63958

Produtos afetados

Linux