Junglewise Threat Intelligence

CVE-2026-63896: Linux Kernel integer underflow in WebUSB GET_URL handling

CVE-2026-63896 · Severity: info · CVSS 0 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the Linux kernel's USB gadget subsystem when handling WebUSB requests. An attacker with physical access or control over a connected USB host can trigger a system crash or memory corruption by sending a specially crafted request. This affects devices configured to use WebUSB with a landing page, potentially impacting the stability and security of embedded Linux systems.

Technical details

An integer underflow vulnerability exists in `drivers/usb/gadget/composite.c` within the `composite_setup()` function. When handling a WebUSB `GET_URL` request, the code fails to validate that the host-supplied `wLength` is greater than the `WEBUSB_URL_DESCRIPTOR_HEADER_LENGTH`. If `wLength` is smaller, an unsigned subtraction wraps around to a very large value, causing `memcpy()` to attempt to copy nearly 4GB of data. This results in a slab-out-of-bounds access and a kernel panic or memory corruption. The vulnerability is reachable via a single USB SETUP packet on gadgets with WebUSB enabled and a landing page configured. Patches have been released for various stable kernel branches.

Affected products

  • Linux Linux Kernel 6.3 to 6.9.x

Timeline

  • 2026-05-12: other: Vulnerability fixed in source code
  • 2026-07-19: disclosed: CVE-2026-63896 published

References

Related threats