Junglewise Threat Intelligence

CVE-2026-63961: Linux Kernel information leak in USB Type-C DisplayPort driver

CVE-2026-63961 · Severity: info · CVSS 0 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's USB Type-C driver could allow a malicious or malfunctioning USB device to access sensitive information. By sending a specially crafted message, a device could trick the computer into reading internal memory that it shouldn't have access to. This could lead to the exposure of private data from the system's memory to the connected device.

Technical details

A vulnerability exists in 'drivers/usb/typec/altmodes/displayport.c' within the Linux kernel. The 'dp_altmode_vdm' function handles 'DP_CMD_STATUS_UPDATE' messages without verifying that the 'count' parameter is sufficient (at least 2) before accessing the VDO data. A malicious or malformed USB device can provide an incorrect count, causing the kernel to read uninitialized stack memory and potentially transmit it back to the device or other components. This is a classic information leak resulting from a lack of input validation on hardware-provided metadata. Patches have been released across multiple stable kernel branches (5.10.y, 5.15.y, 6.1.y, 6.6.y, 6.12.y, 6.18.y, and 7.0.y).

Affected products

  • Linux Linux Kernel 5.10.259, 5.15.210, 6.1.176, 6.6.143, 6.12.93, 6.18.35, 7.0.12

Timeline

  • 2026-07-19: disclosed: CVE published and kernel patches identified.

References

Related threats