SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-63943

UNKNOWN · CVSS N/A EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-07-19 · Last synced 2026-08-18

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's xpad driver, specifically in the handling of input packets from game controllers. An attacker could exploit this flaw by sending a malformed packet, leading to potential out-of-bounds memory access, which may result in system instability or arbitrary code execution. Organizations using Linux systems with affected xpad drivers should prioritize patching this vulnerability to mitigate risks associated with compromised input devices.

CVE
CVE-2026-63943
Severity
UNKNOWN
CVSS
N/A
EPSS
0.20%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: Input: xpad - fix out-of-bounds access for Share button xpadone_process_packet() receives len directly from urb->actual_length and uses it to index the share-button byte at data[len - 18] or data[len - 26]. Since both len and data[0] are under the device's control, a broken controller can send a GIP_CMD_INPUT packet with actual_length < 18 (e.g. 5 bytes) and reach this code path, causing accesses beyond the actual array. Fix this by calculating the offset and checking bounds against the packet length.