USB: serial: mxuport: fix memory corruption with small endpoint
Make sure that the bulk-out endpoint max packet size is at least eight
bytes to avoid user-controlled slab corruption should a malicious device
report a smaller size.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Ubuntu USN |
USN-8593-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-8603-1 | Linux kernel (Azure) vulnerabilities |
Ubuntu USN |
USN-8618-1 | Linux kernel vulnerabilities |
Wed, 22 Jul 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-120 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Sun, 19 Jul 2026 15:30:00 +0000
Status: PUBLISHED
Assigner: Linux
Published:
Updated: 2026-07-19T14:55:08.116Z
Reserved: 2026-07-19T07:54:57.019Z
Link: CVE-2026-63899
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-27T20:30:09Z
-
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Ubuntu USN