-
CVE-2026-63958
- EPSS 0.21%
- Veröffentlicht 19.07.2026 14:55:48
- Zuletzt bearbeitet 30.07.2026 14:51:11
- CVE-Watchlists
- Unerledigt
usb: typec: ucsi: validate connector number in ucsi_connector_change()
In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: validate connector number in ucsi_connector_change() The connector number in a UCSI CCI notification is a 7-bit field supplied by the PPM. ucsi_connector_change() uses it to index the ucsi->connector[] array without checking it against the number of connectors the PPM reported at init time, so a buggy or malicious PPM (EC firmware, or an I2C-attached UCSI controller on the ccg / stm32g0 / glink transports) can drive schedule_work() on memory past the end of the array. Reject connector numbers that are zero or exceed cap.num_connectors before dereferencing the array.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
c1b0bc2dabfa884dea49c02adaf3cd6b52b33d2f
Version <
cea949203faef9cb783adc7b978cce056271e057
Status
affected
Version
c1b0bc2dabfa884dea49c02adaf3cd6b52b33d2f
Version <
156b6f0aec6108909b0c4aedc78865b12766b347
Status
affected
Version
c1b0bc2dabfa884dea49c02adaf3cd6b52b33d2f
Version <
bd24d92af4ae021b6209f28e9a57e1bf2260d4fd
Status
affected
Version
c1b0bc2dabfa884dea49c02adaf3cd6b52b33d2f
Version <
0edd1e21587b0483c7ceb993b9fb9668bbef7433
Status
affected
Version
c1b0bc2dabfa884dea49c02adaf3cd6b52b33d2f
Version <
5af2719b460ab904c504fc069d1dd2a3aa2b22b0
Status
affected
Version
c1b0bc2dabfa884dea49c02adaf3cd6b52b33d2f
Version <
288a81a8507052bcfbf884d39a463c44c42c5fd9
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
4.13
Status
affected
Version
0
Version <
4.13
Status
unaffected
Version <=
6.1.*
Version
6.1.176
Status
unaffected
Version <=
6.6.*
Version
6.6.143
Status
unaffected
Version <=
6.12.*
Version
6.12.93
Status
unaffected
Version <=
6.18.*
Version
6.18.35
Status
unaffected
Version <=
7.0.*
Version
7.0.12
Status
unaffected
Version <=
*
Version
7.1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.21% | 0.116 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/cea949203faef9cb783adc7b978cce056271e057
https://git.kernel.org/stable/c/156b6f0aec6108909b0c4aedc78865b12766b347
https://git.kernel.org/stable/c/bd24d92af4ae021b6209f28e9a57e1bf2260d4fd
https://git.kernel.org/stable/c/0edd1e21587b0483c7ceb993b9fb9668bbef7433
https://git.kernel.org/stable/c/5af2719b460ab904c504fc069d1dd2a3aa2b22b0
https://git.kernel.org/stable/c/288a81a8507052bcfbf884d39a463c44c42c5fd9