Junglewise Threat Intelligence

CVE-2026-63959: Linux Kernel uninitialized memory read in USB Type-C Maxim driver

CVE-2026-63959 · Severity: info · CVSS 4.3 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's USB Type-C driver could allow a malicious USB device to cause a system crash or leak sensitive information. By sending a specially crafted but technically valid data frame, the device can trick the system into reading uninitialized memory. This requires physical access to the device's USB port.

Technical details

A vulnerability exists in the `process_rx` function within `drivers/usb/typec/tcpm/tcpci_maxim_core.c` of the Linux kernel. The driver processes USB Power Delivery (PD) frames and trusts the Number of Data Objects (NDO) field in the frame header without verifying that the actual received byte count (`RX_BYTE_CNT`) matches the advertised length. A malicious or malfunctioning USB port can send a CRC-valid frame that claims to contain up to seven data objects but provides fewer, causing the driver to read beyond the received data into uninitialized stack memory. This can result in a kernel oops (denial of service) or the disclosure of sensitive kernel stack information. The issue has been patched in several stable branches including 6.6.143, 6.12.93, 6.18.35, and 7.0.12.

Affected products

  • Linux Linux Kernel 6.6.143, 6.12.93, 6.18.35, 7.0.12, 7.1

Timeline

  • 2026-05-13: patched: Initial fix authored by Greg Kroah-Hartman
  • 2026-07-19: disclosed: CVE published to NVD dataset

References

Related threats