CVE-2026-63892

Source
https://cve.org/CVERecord?id=CVE-2026-63892
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63892.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-63892
Downstream
Published
2026-07-19T14:55:03.568Z
Modified
2026-07-21T03:47:31.671361201Z
Summary
thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow
Details

In the Linux kernel, the following vulnerability has been resolved:

thunderbolt: property: Reject dirlen < 4 to prevent sizet underflow

On the non-root path, _tbpropertyparsedir() takes dirlen from entry->length (u16 widened to sizet). Two distinct OOB conditions follow when entry->length < 4:

  1. The non-root path begins with kmemdup(&block[diroffset], sizeof(*dir->uuid), ...) which always reads 4 dwords from diroffset. tbpropertyentryvalid() only enforces diroffset + entry->length <= blocklen, so a crafted entry with diroffset close to the end of the property block and entry->length in 0..3 passes that gate but lets the UUID copy run off the block (e.g. diroffset = 497, dirlen = 3 in a 500-dword block reads block[497..501]).

  2. After the kmemdup, contentlen = dirlen - 4 underflows sizet to ~SIZEMAX, nentries becomes SIZE_MAX / 4, and the entry walk runs OOB on each iteration until an entry fails validation or the kernel oopses on an unmapped page.

Reject dir_len < 4 on the non-root path before the UUID kmemdup, which closes both holes.

Also move INITLISTHEAD(&dir->properties) up to immediately after the dir allocation so the new error-return path (and the existing uuid-alloc failure path) calling tbpropertyfreedir() sees a walkable list rather than the zero-initialized NULL next/prev that listforeachentry_safe() would oops on.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63892.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
cdae7c07e3e3509eaabc18c1640a55dc5b99c179
Fixed
37abc4504fa19d8f9f1e87792e8a2b8fdb308e40
Fixed
e2d4d51cf5785815fa4e91e0c019e3eb2506a84c
Fixed
de618299190b418291609e6921557253bd417e25
Fixed
5506c825f14d810f0690b1f4367cb7249ebb387a
Fixed
542a13890b742099c461d70920e97b14e568f6ec
Fixed
d548179adcc87e1bc66b17e00352a1f536e76065
Fixed
3bec49ca55e08fb085cc4318f24b1b37eaab28cb
Fixed
de21b59c29e31c5108ddc04210631bbfab81b997

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63892.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.15.0
Fixed
5.10.259
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.210
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.176
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.143
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.93
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.35
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.12

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63892.json"