CVE-2026-63956

Source
https://cve.org/CVERecord?id=CVE-2026-63956
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63956.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-63956
Downstream
Published
2026-07-19T14:55:47.597Z
Modified
2026-07-21T03:47:41.796515515Z
Summary
USB: serial: cypress_m8: fix memory corruption with small endpoint
Details

In the Linux kernel, the following vulnerability has been resolved:

USB: serial: cypress_m8: fix memory corruption with small endpoint

Make sure that the interrupt-out endpoint max packet size is at least eight bytes to avoid user-controlled slab corruption or NULL-pointer dereference should a malicious device report a smaller size.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63956.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
3416eaa1f8f8d516b77de514e14cf8da256d28fb
Fixed
4fcb22218f0a7229b7ce3b3952fb644def293fa5
Fixed
ad3d1628a46134276546d7a12fedf04be9979158
Fixed
52e18ae0c47c5c89e18fcd8022f287f7cc8802ec
Fixed
4bcaa59f403dbde6328604a500d65ee8d40975d9
Fixed
1ef25704bd3b625fd151c09feee459479f71ee64
Fixed
284105c40fc31fff90cdab8a0377aaeb92f87f0e
Fixed
6c13f3bb652bc8665e709ba07122612586aea648
Fixed
e1a9d791fd66ab2431b9e6f6f835823809869047

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63956.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.26
Fixed
5.10.259
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.210
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.176
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.143
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.93
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.35
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.12

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63956.json"