CVE-2026-63904

Source
https://cve.org/CVERecord?id=CVE-2026-63904
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63904.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-63904
Downstream
Published
2026-07-19T14:55:11.547Z
Modified
2026-07-21T03:47:38.154494609Z
Summary
usb: usbtmc: check URB actual_length for interrupt-IN notifications
Details

In the Linux kernel, the following vulnerability has been resolved:

usb: usbtmc: check URB actual_length for interrupt-IN notifications

USBTMC devices can use an optional interrupt endpoint for notification messages. These typically contain two-byte headers indicating the payload format, but the driver does not check if these headers are present before accessing the data buffers. In cases where the URB actual_length is not enough to fit these headers, the driver will either cause an out-of-bounds read, or consume stale leftover data from a previous notification.

Fix by checking if actual_data contains enough bytes for the headers, otherwise resubmit URB to the interrupt endpoint.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63904.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
dbf3e7f654c0f06a932b8fcafac78de9d0b81d68
Fixed
e794bd67b3faf98af46f958897f6b91412c7d2a9
Fixed
e3eec3005de44e7f37d8d7724be636446516ab42
Fixed
ae87f505917e703ae3b487d9663d78826ff43608
Fixed
5de7df75ef3a2756b25fe3d582a4a2970444fe5a
Fixed
69020fa089f1bf0e1a10a15265f31b143a846409
Fixed
75f6d3da2cc646983f41807ef98851569c12bca9
Fixed
f141b01eaa58ac7e323931d670318aa247bff087
Fixed
52f2ad3f7e5eb3b5908e1d685d4342519dc9cfcd

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63904.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.6.0
Fixed
5.10.259
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.210
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.176
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.143
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.93
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.35
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.12

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63904.json"