« Volver al listado

CVE-2026-63958

Estado: Pendiente de análisisSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

usb: typec: ucsi: validate connector number in ucsi_connector_change()

The connector number in a UCSI CCI notification is a 7-bit field supplied by the PPM. ucsi_connector_change() uses it to index the ucsi->connector[] array without checking it against the number of connectors the PPM reported at init time, so a buggy or malicious PPM (EC firmware, or an I2C-attached UCSI controller on the ccg / stm32g0 / glink transports) can drive schedule_work() on memory past the end of the array.

Reject connector numbers that are zero or exceed cap.num_connectors before dereferencing the array.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-63958",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "c1b0bc2dabfa884dea49c02adaf3cd6b52b33d2f",
              "lessThan": "cea949203faef9cb783adc7b978cce056271e057",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c1b0bc2dabfa884dea49c02adaf3cd6b52b33d2f",
              "lessThan": "156b6f0aec6108909b0c4aedc78865b12766b347",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c1b0bc2dabfa884dea49c02adaf3cd6b52b33d2f",
              "lessThan": "bd24d92af4ae021b6209f28e9a57e1bf2260d4fd",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c1b0bc2dabfa884dea49c02adaf3cd6b52b33d2f",
              "lessThan": "0edd1e21587b0483c7ceb993b9fb9668bbef7433",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c1b0bc2dabfa884dea49c02adaf3cd6b52b33d2f",
              "lessThan": "5af2719b460ab904c504fc069d1dd2a3aa2b22b0",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c1b0bc2dabfa884dea49c02adaf3cd6b52b33d2f",
              "lessThan": "288a81a8507052bcfbf884d39a463c44c42c5fd9",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/usb/typec/ucsi/ucsi.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.13"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.13",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.1.176",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.143",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.93",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.35",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.0.12",
              "versionType": "semver",
              "lessThanOrEqual": "7.0.*"
            },
            {
              "status": "unaffected",
              "version": "7.1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/usb/typec/ucsi/ucsi.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-07-19T16:17:14.667",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0edd1e21587b0483c7ceb993b9fb9668bbef7433",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/156b6f0aec6108909b0c4aedc78865b12766b347",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/288a81a8507052bcfbf884d39a463c44c42c5fd9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/5af2719b460ab904c504fc069d1dd2a3aa2b22b0",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/bd24d92af4ae021b6209f28e9a57e1bf2260d4fd",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/cea949203faef9cb783adc7b978cce056271e057",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Awaiting Analysis",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: ucsi: validate connector number in ucsi_connector_change()\n\nThe connector number in a UCSI CCI notification is a 7-bit field\nsupplied by the PPM.  ucsi_connector_change() uses it to index the\nucsi->connector[] array without checking it against the number of\nconnectors the PPM reported at init time, so a buggy or malicious PPM\n(EC firmware, or an I2C-attached UCSI controller on the ccg / stm32g0 /\nglink transports) can drive schedule_work() on memory past the end of\nthe array.\n\nReject connector numbers that are zero or exceed cap.num_connectors\nbefore dereferencing the array."
    }
  ],
  "lastModified": "2026-07-30T14:51:11.223",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}