In the Linux kernel, the following vulnerability has been resolved:
usb: typec: ucsi: validate connector number in ucsiconnectorchange()
The connector number in a UCSI CCI notification is a 7-bit field supplied by the PPM. ucsiconnectorchange() uses it to index the ucsi->connector[] array without checking it against the number of connectors the PPM reported at init time, so a buggy or malicious PPM (EC firmware, or an I2C-attached UCSI controller on the ccg / stm32g0 / glink transports) can drive schedule_work() on memory past the end of the array.
Reject connector numbers that are zero or exceed cap.num_connectors before dereferencing the array.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63958.json",
"cna_assigner": "Linux"
}