SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-63904

UNKNOWN · CVSS N/A EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-07-19 · Last synced 2026-08-18

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's USB Test & Measurement Class (USBTMC) driver, which fails to validate the actual length of data received from interrupt notifications. This oversight can lead to out-of-bounds reads or the use of stale data, potentially compromising system stability or security. Organizations using Linux systems with USBTMC devices should prioritize this issue to mitigate risks associated with data integrity and system reliability.

CVE
CVE-2026-63904
Severity
UNKNOWN
CVSS
N/A
EPSS
0.21%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: usb: usbtmc: check URB actual_length for interrupt-IN notifications USBTMC devices can use an optional interrupt endpoint for notification messages. These typically contain two-byte headers indicating the payload format, but the driver does not check if these headers are present before accessing the data buffers. In cases where the URB actual_length is not enough to fit these headers, the driver will either cause an out-of-bounds read, or consume stale leftover data from a previous notification. Fix by checking if actual_data contains enough bytes for the headers, otherwise resubmit URB to the interrupt endpoint.