CVE-2026-63891
In the Linux kernel, the following vulnerability has been resolved:
thunderbolt: property: Cap recursion depth in __tb_property_parse_dir()
A DIRECTORY entry's value field is used as the dir_offset for a recursive call into __tb_property_parse_dir() with no depth counter. A crafted peer that chains DIRECTORY entries into a back-reference loop drives the parser until the kernel stack is exhausted and the guard page fires. Any untrusted XDomain peer (cable, dock, in-line inspector, adjacent host) that reaches the PROPERTIES_REQUEST control-plane exchange can trigger this without authentication.
Thread a depth counter through tb_property_parse() and __tb_property_parse_dir(), and reject blocks that exceed TB_PROPERTY_MAX_DEPTH = 8. That is comfortably larger than any observed legitimate XDomain layout.
Leer descripción completaMostrar menos
Operators who do not need XDomain host-to-host discovery can disable the path entirely with thunderbolt.xdomain=0 on the kernel command line.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.27%
- Percentil entre todas las CVEs puntuadas: 18
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/0a84ab9271936c11e84e511bb52fc5682f8b6726
- https://git.kernel.org/stable/c/2b5f47a710172c962ef42d1b732b04d2ad0dce21
- https://git.kernel.org/stable/c/830c8a9b467e7d3a158483d37fa7dc13892b293a
- https://git.kernel.org/stable/c/928abe19fbf0127003abcb1ea69cabc1c897d0ab
- https://git.kernel.org/stable/c/95839a67ea56ca35732aad7f711404a3127cfe2d
- https://git.kernel.org/stable/c/b4621e5ef63405c317a84b711faf3bd75b3c6a94
- https://git.kernel.org/stable/c/ed9455ef4bd9babc90f92e526abe3fb68c1a8709
- https://git.kernel.org/stable/c/f31c6d220f455b5af63590302b30e1b932d14599
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-63891",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "cdae7c07e3e3509eaabc18c1640a55dc5b99c179",
"lessThan": "2b5f47a710172c962ef42d1b732b04d2ad0dce21",
"versionType": "git"
},
{
"status": "affected",
"version": "cdae7c07e3e3509eaabc18c1640a55dc5b99c179",
"lessThan": "95839a67ea56ca35732aad7f711404a3127cfe2d",
"versionType": "git"
},
{
"status": "affected",
"version": "cdae7c07e3e3509eaabc18c1640a55dc5b99c179",
"lessThan": "0a84ab9271936c11e84e511bb52fc5682f8b6726",
"versionType": "git"
},
{
"status": "affected",
"version": "cdae7c07e3e3509eaabc18c1640a55dc5b99c179",
"lessThan": "b4621e5ef63405c317a84b711faf3bd75b3c6a94",
"versionType": "git"
},
{
"status": "affected",
"version": "cdae7c07e3e3509eaabc18c1640a55dc5b99c179",
"lessThan": "f31c6d220f455b5af63590302b30e1b932d14599",
"versionType": "git"
},
{
"status": "affected",
"version": "cdae7c07e3e3509eaabc18c1640a55dc5b99c179",
"lessThan": "830c8a9b467e7d3a158483d37fa7dc13892b293a",
"versionType": "git"
},
{
"status": "affected",
"version": "cdae7c07e3e3509eaabc18c1640a55dc5b99c179",
"lessThan": "ed9455ef4bd9babc90f92e526abe3fb68c1a8709",
"versionType": "git"
},
{
"status": "affected",
"version": "cdae7c07e3e3509eaabc18c1640a55dc5b99c179",
"lessThan": "928abe19fbf0127003abcb1ea69cabc1c897d0ab",
"versionType": "git"
}
],
"programFiles": [
"drivers/thunderbolt/property.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4.15"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "4.15",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.259",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.210",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.93",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.35",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.0.12",
"versionType": "semver",
"lessThanOrEqual": "7.0.*"
},
{
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/thunderbolt/property.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-07-19T16:17:06.440",
"references": [
{
"url": "https://git.kernel.org/stable/c/0a84ab9271936c11e84e511bb52fc5682f8b6726",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/2b5f47a710172c962ef42d1b732b04d2ad0dce21",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/830c8a9b467e7d3a158483d37fa7dc13892b293a",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/928abe19fbf0127003abcb1ea69cabc1c897d0ab",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/95839a67ea56ca35732aad7f711404a3127cfe2d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/b4621e5ef63405c317a84b711faf3bd75b3c6a94",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/ed9455ef4bd9babc90f92e526abe3fb68c1a8709",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f31c6d220f455b5af63590302b30e1b932d14599",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Awaiting Analysis",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nthunderbolt: property: Cap recursion depth in __tb_property_parse_dir()\n\nA DIRECTORY entry's value field is used as the dir_offset for a\nrecursive call into __tb_property_parse_dir() with no depth counter.\nA crafted peer that chains DIRECTORY entries into a back-reference\nloop drives the parser until the kernel stack is exhausted and the\nguard page fires. Any untrusted XDomain peer (cable, dock, in-line\ninspector, adjacent host) that reaches the PROPERTIES_REQUEST\ncontrol-plane exchange can trigger this without authentication.\n\nThread a depth counter through tb_property_parse() and\n__tb_property_parse_dir(), and reject blocks that exceed\nTB_PROPERTY_MAX_DEPTH = 8. That is comfortably larger than any\nobserved legitimate XDomain layout.\n\nOperators who do not need XDomain host-to-host discovery can disable\nthe path entirely with thunderbolt.xdomain=0 on the kernel command\nline."
}
],
"lastModified": "2026-07-27T17:44:23.777",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}