CVE-2026-63959

Source
https://cve.org/CVERecord?id=CVE-2026-63959
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-63959.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-63959
Downstream
Published
2026-07-19T14:55:49.553Z
Modified
2026-07-22T03:32:07.574827694Z
Summary
usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT
Details

In the Linux kernel, the following vulnerability has been resolved:

usb: typec: tcpm/tcpcimaxim: validate header NDO against RXBYTE_CNT

A broken/malicious port can transmit a CRC-valid frame whose header advertises up to seven data objects but whose body carries fewer than that. Check for this, and rightfully reject the message, instead of reading from uninitialized stack memory.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63959.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
6f413b559f86a2894188e082e389ff95ee428345
Fixed
0af00f1459f5dd757f0d392f8caa38039561ac62
Fixed
dc17721d42e6d89f63572e63add8306a0e15eb3c
Fixed
9b496e3371c04f0a03b7faa5d2442536d00e3998
Fixed
c4ab8e2d4432abb646c5c0687f8dab173da901f9
Fixed
aa2f716327be1818e1cb156da8a2844804aaec2f

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-63959.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.10.0
Fixed
6.6.143
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.93
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.35
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.12

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-63959.json"