CVE-2026-63899

Source
https://cve.org/CVERecord?id=CVE-2026-63899
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63899.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-63899
Downstream
Published
2026-07-19T14:55:08.116Z
Modified
2026-07-21T03:47:39.788661172Z
Summary
USB: serial: mxuport: fix memory corruption with small endpoint
Details

In the Linux kernel, the following vulnerability has been resolved:

USB: serial: mxuport: fix memory corruption with small endpoint

Make sure that the bulk-out endpoint max packet size is at least eight bytes to avoid user-controlled slab corruption should a malicious device report a smaller size.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63899.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ee467a1f2066d2bfa293f7c2c7f1ff7000b0a39e
Fixed
086b858b5f5125bc9d967ea2bd825f83d9f8f29d
Fixed
2f3661eb2446e1ef593da45e01a3b21a906768ec
Fixed
ccbec56f2f9af008f1574335cc6a668f16603e47
Fixed
be3a1ed4ae51fa8dde57383277d336ce834f2cd9
Fixed
e906545641d34fb1a09a65b4b5cfdff40eb09681
Fixed
6c0cf56f00f280d72180bb6ce79741bc787a6269
Fixed
b40166b4ef96067620a0f248e74ad9658c8f680c
Fixed
4085f0dbb1ce2251c9a5938d693de6593f0ab2bd

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63899.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.14.0
Fixed
5.10.259
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.210
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.176
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.143
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.93
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.35
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.12

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63899.json"