๐Ÿ” CVE Alert

CVE-2026-63893

UNKNOWN 0.0

thunderbolt: property: Reject u32 wrap in tb_property_entry_valid()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() entry->value is u32 and entry->length is u16; the sum is performed in u32 and wraps. A malicious XDomain peer can pick value = 0xffffff00, length = 0x100 so the sum 0x100000000 wraps to 0 and passes the > block_len check. tb_property_parse() then passes entry->value to parse_dwdata() as a dword offset into the property block, reading attacker-directed memory far past the allocation. For TEXT-typed entries with the "deviceid" or "vendorid" keys this lands in xd->device_name / xd->vendor_name and is readable back via the per-XDomain device_name / vendor_name sysfs attributes; the leak is NUL-bounded (kstrdup() stops at the first zero byte) and untargeted (the attacker picks a delta, not an absolute address). DATA-typed entries are parsed into property->value.data but not generically surfaced to userspace. Use check_add_overflow() so a wrapped sum is rejected.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jul 19, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
cdae7c07e3e3509eaabc18c1640a55dc5b99c179 < 6a63623621639acbb39bc2d9fb09559681716695 cdae7c07e3e3509eaabc18c1640a55dc5b99c179 < e8a0b0a93a6ef958e70b1dd4930beb6dc0026b36 cdae7c07e3e3509eaabc18c1640a55dc5b99c179 < 9fee50c4e1e42f6d3cbe30df584f9f648f626071 cdae7c07e3e3509eaabc18c1640a55dc5b99c179 < 8d4a758b407ab3de3be86d1ceadfa35d717d30c7 cdae7c07e3e3509eaabc18c1640a55dc5b99c179 < 5c06a3043ad944f087bb2ae0aae28d820bb9f460 cdae7c07e3e3509eaabc18c1640a55dc5b99c179 < 31b98e503ecca8077e5247253dd5425ab84bc96d cdae7c07e3e3509eaabc18c1640a55dc5b99c179 < a47784aee77f33f786dc5d7375db821bdae68792 cdae7c07e3e3509eaabc18c1640a55dc5b99c179 < 01deda0152066c6c955f0619114ea6afa070aaec
Linux / Linux
4.15

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/6a63623621639acbb39bc2d9fb09559681716695 git.kernel.org: https://git.kernel.org/stable/c/e8a0b0a93a6ef958e70b1dd4930beb6dc0026b36 git.kernel.org: https://git.kernel.org/stable/c/9fee50c4e1e42f6d3cbe30df584f9f648f626071 git.kernel.org: https://git.kernel.org/stable/c/8d4a758b407ab3de3be86d1ceadfa35d717d30c7 git.kernel.org: https://git.kernel.org/stable/c/5c06a3043ad944f087bb2ae0aae28d820bb9f460 git.kernel.org: https://git.kernel.org/stable/c/31b98e503ecca8077e5247253dd5425ab84bc96d git.kernel.org: https://git.kernel.org/stable/c/a47784aee77f33f786dc5d7375db821bdae68792 git.kernel.org: https://git.kernel.org/stable/c/01deda0152066c6c955f0619114ea6afa070aaec