CVE-2026-63961

Source
https://cve.org/CVERecord?id=CVE-2026-63961
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-63961.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-63961
Downstream
Published
2026-07-19T14:55:50.993Z
Modified
2026-07-22T03:32:00.619537198Z
Summary
usb: typec: altmodes/displayport: validate count before reading Status Update VDO
Details

In the Linux kernel, the following vulnerability has been resolved:

usb: typec: altmodes/displayport: validate count before reading Status Update VDO

A broken/malicious device can send the incorrect count for a status update VDO, which will cause the kernel to read uninitialized stack data and send it off elsewhere.

Fix this up by correctly verifying the count for the update object.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63961.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0e3bb7d6894d9b6e67d6382bb03a46a1dc989588
Fixed
74aabe9ea30fdfba924fce9594e6aa69a596a4bb
Fixed
dd7118c010f324497c275e8fd7a35c9baaa2a00f
Fixed
6ffdbcd7a02f3af8fff9b6519830369f574ed44c
Fixed
70e7045849e954e56dcbf441b6330e66bc996306
Fixed
64bd6ccc5799f8473d1f37d4d8f53093dfec5c02
Fixed
b10eff5abe6aa2a5af10ed17bddff76e3b6e6b9b
Fixed
77a759ec30bc5fb0dd9c867b711d0acfed6c7faa
Fixed
8a18f896e667df491331371b55d4ad644dc51d60

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-63961.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.19.0
Fixed
5.10.259
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.210
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.176
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.143
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.93
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.35
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.12

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-63961.json"