« Volver al listado

CVE-2026-63964

Estado: Pendiente de análisisSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

usb: typec: ucsi: ccg: reject firmware images without a ':' record header

do_flash() locates the first .cyacd record with

If the firmware image contains no ':' byte, strnchr() returns NULL. NULL compares less than the valid kernel pointer eof, so the loop body runs and strnchr() is called with p + 1 == (void *)1 and a length of roughly (unsigned long)eof, causing a wonderful crash.

The not_signed_fw fallthrough earlier in do_flash() and the chip-state branches in ccg_fw_update_needed() allow an unsigned blob to reach this loop, so a root user who can place a crafted file under /lib/firmware and write the do_flash sysfs attribute can trigger the oops.

Leer descripción completaMostrar menos

Bail out with -EINVAL when the initial strnchr() returns NULL.

Detalles técnicos trazas, registros y código del informe original
	p = strnchr(fw->data, fw->size, ':');
	while (p < eof) {
		s = strnchr(p + 1, eof - p - 1, ':');
		...
	}

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-63964",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5c9ae5a87573d38cfc4c740aafda2fa6ce06e401",
              "lessThan": "b41dfc033fe594e152648050e95b9489cd53e9e3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5c9ae5a87573d38cfc4c740aafda2fa6ce06e401",
              "lessThan": "2f395ca1263bd181995eb829f5943a83a20db213",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5c9ae5a87573d38cfc4c740aafda2fa6ce06e401",
              "lessThan": "6526f8684f72391138353642af908803ba70795e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5c9ae5a87573d38cfc4c740aafda2fa6ce06e401",
              "lessThan": "3f432b8203066c26770fe6ea591361f10021dd6b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5c9ae5a87573d38cfc4c740aafda2fa6ce06e401",
              "lessThan": "c4ee519b06389e59ba2d6aa722fcc4a02a8bbcbb",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5c9ae5a87573d38cfc4c740aafda2fa6ce06e401",
              "lessThan": "a38ed87818b2419090fb1a6338ddce6842b65dfa",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5c9ae5a87573d38cfc4c740aafda2fa6ce06e401",
              "lessThan": "c8460de584fe5415d212cfdd127d4db90835a450",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5c9ae5a87573d38cfc4c740aafda2fa6ce06e401",
              "lessThan": "d7486952bf74e546ee3748fb14b2d07881fa6273",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/usb/typec/ucsi/ucsi_ccg.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.2"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.2",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.259",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.210",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.176",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.143",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.93",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.35",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.0.12",
              "versionType": "semver",
              "lessThanOrEqual": "7.0.*"
            },
            {
              "status": "unaffected",
              "version": "7.1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/usb/typec/ucsi/ucsi_ccg.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-07-19T16:17:15.370",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/2f395ca1263bd181995eb829f5943a83a20db213",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/3f432b8203066c26770fe6ea591361f10021dd6b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6526f8684f72391138353642af908803ba70795e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a38ed87818b2419090fb1a6338ddce6842b65dfa",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b41dfc033fe594e152648050e95b9489cd53e9e3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c4ee519b06389e59ba2d6aa722fcc4a02a8bbcbb",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c8460de584fe5415d212cfdd127d4db90835a450",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d7486952bf74e546ee3748fb14b2d07881fa6273",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Awaiting Analysis",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: ucsi: ccg: reject firmware images without a ':' record header\n\ndo_flash() locates the first .cyacd record with\n\n\tp = strnchr(fw->data, fw->size, ':');\n\twhile (p < eof) {\n\t\ts = strnchr(p + 1, eof - p - 1, ':');\n\t\t...\n\t}\n\nIf the firmware image contains no ':' byte,  strnchr() returns NULL.\nNULL compares less than the valid kernel pointer eof, so the loop body\nruns and strnchr() is called with p + 1 == (void *)1 and a length of\nroughly (unsigned long)eof, causing a wonderful crash.\n\nThe not_signed_fw fallthrough earlier in do_flash() and the chip-state\nbranches in ccg_fw_update_needed() allow an unsigned blob to reach this\nloop, so a root user who can place a crafted file under /lib/firmware\nand write the do_flash sysfs attribute can trigger the oops.\n\nBail out with -EINVAL when the initial strnchr() returns NULL."
    }
  ],
  "lastModified": "2026-07-30T14:51:11.223",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}