Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92783.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-92783
Upstream
Published
2026-07-19T16:17:15Z
Modified
2026-08-28T17:45:12Z
Summary
CVE-2026-63961 affecting package kernel for versions less than 6.6.144.1-2
Details

In the Linux kernel, the following vulnerability has been resolved:

usb: typec: altmodes/displayport: validate count before reading Status Update VDO

A broken/malicious device can send the incorrect count for a status update VDO, which will cause the kernel to read uninitialized stack data and send it off elsewhere.

Fix this up by correctly verifying the count for the update object.

References

Affected packages

Azure Linux:3 / kernel

Package

Name
kernel
Purl
pkg:rpm/azure-linux/kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
6.6.144.1-2

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92783.json"