๐Ÿ” CVE Alert

CVE-2026-63892

UNKNOWN 0.0

thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow On the non-root path, __tb_property_parse_dir() takes dir_len from entry->length (u16 widened to size_t). Two distinct OOB conditions follow when entry->length < 4: 1. The non-root path begins with kmemdup(&block[dir_offset], sizeof(*dir->uuid), ...) which always reads 4 dwords from dir_offset. tb_property_entry_valid() only enforces dir_offset + entry->length <= block_len, so a crafted entry with dir_offset close to the end of the property block and entry->length in 0..3 passes that gate but lets the UUID copy run off the block (e.g. dir_offset = 497, dir_len = 3 in a 500-dword block reads block[497..501]). 2. After the kmemdup, content_len = dir_len - 4 underflows size_t to ~SIZE_MAX, nentries becomes SIZE_MAX / 4, and the entry walk runs OOB on each iteration until an entry fails validation or the kernel oopses on an unmapped page. Reject dir_len < 4 on the non-root path *before* the UUID kmemdup, which closes both holes. Also move INIT_LIST_HEAD(&dir->properties) up to immediately after the dir allocation so the new error-return path (and the existing uuid-alloc failure path) calling tb_property_free_dir() sees a walkable list rather than the zero-initialized NULL next/prev that list_for_each_entry_safe() would oops on.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jul 19, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
cdae7c07e3e3509eaabc18c1640a55dc5b99c179 < 37abc4504fa19d8f9f1e87792e8a2b8fdb308e40 cdae7c07e3e3509eaabc18c1640a55dc5b99c179 < e2d4d51cf5785815fa4e91e0c019e3eb2506a84c cdae7c07e3e3509eaabc18c1640a55dc5b99c179 < de618299190b418291609e6921557253bd417e25 cdae7c07e3e3509eaabc18c1640a55dc5b99c179 < 5506c825f14d810f0690b1f4367cb7249ebb387a cdae7c07e3e3509eaabc18c1640a55dc5b99c179 < 542a13890b742099c461d70920e97b14e568f6ec cdae7c07e3e3509eaabc18c1640a55dc5b99c179 < d548179adcc87e1bc66b17e00352a1f536e76065 cdae7c07e3e3509eaabc18c1640a55dc5b99c179 < 3bec49ca55e08fb085cc4318f24b1b37eaab28cb cdae7c07e3e3509eaabc18c1640a55dc5b99c179 < de21b59c29e31c5108ddc04210631bbfab81b997
Linux / Linux
4.15

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/37abc4504fa19d8f9f1e87792e8a2b8fdb308e40 git.kernel.org: https://git.kernel.org/stable/c/e2d4d51cf5785815fa4e91e0c019e3eb2506a84c git.kernel.org: https://git.kernel.org/stable/c/de618299190b418291609e6921557253bd417e25 git.kernel.org: https://git.kernel.org/stable/c/5506c825f14d810f0690b1f4367cb7249ebb387a git.kernel.org: https://git.kernel.org/stable/c/542a13890b742099c461d70920e97b14e568f6ec git.kernel.org: https://git.kernel.org/stable/c/d548179adcc87e1bc66b17e00352a1f536e76065 git.kernel.org: https://git.kernel.org/stable/c/3bec49ca55e08fb085cc4318f24b1b37eaab28cb git.kernel.org: https://git.kernel.org/stable/c/de21b59c29e31c5108ddc04210631bbfab81b997