CVE-2026-63891

Source
https://cve.org/CVERecord?id=CVE-2026-63891
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63891.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-63891
Downstream
Published
2026-07-19T14:55:02.840Z
Modified
2026-07-21T03:47:31.694805306Z
Summary
thunderbolt: property: Cap recursion depth in __tb_property_parse_dir()
Details

In the Linux kernel, the following vulnerability has been resolved:

thunderbolt: property: Cap recursion depth in _tbpropertyparsedir()

A DIRECTORY entry's value field is used as the dir_offset for a recursive call into __tbpropertyparsedir() with no depth counter. A crafted peer that chains DIRECTORY entries into a back-reference loop drives the parser until the kernel stack is exhausted and the guard page fires. Any untrusted XDomain peer (cable, dock, in-line inspector, adjacent host) that reaches the PROPERTIESREQUEST control-plane exchange can trigger this without authentication.

Thread a depth counter through tbpropertyparse() and __tbpropertyparsedir(), and reject blocks that exceed TBPROPERTYMAXDEPTH = 8. That is comfortably larger than any observed legitimate XDomain layout.

Operators who do not need XDomain host-to-host discovery can disable the path entirely with thunderbolt.xdomain=0 on the kernel command line.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63891.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
cdae7c07e3e3509eaabc18c1640a55dc5b99c179
Fixed
2b5f47a710172c962ef42d1b732b04d2ad0dce21
Fixed
95839a67ea56ca35732aad7f711404a3127cfe2d
Fixed
0a84ab9271936c11e84e511bb52fc5682f8b6726
Fixed
b4621e5ef63405c317a84b711faf3bd75b3c6a94
Fixed
f31c6d220f455b5af63590302b30e1b932d14599
Fixed
830c8a9b467e7d3a158483d37fa7dc13892b293a
Fixed
ed9455ef4bd9babc90f92e526abe3fb68c1a8709
Fixed
928abe19fbf0127003abcb1ea69cabc1c897d0ab

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63891.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.15.0
Fixed
5.10.259
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.210
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.176
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.143
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.93
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.35
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.12

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63891.json"