Junglewise Threat Intelligence

CVE-2026-63962: Linux Kernel buffer overflow in USB Type-C TCPM svdm_consume_modes

CVE-2026-63962 · Severity: info · CVSS 0 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's USB Type-C Port Manager could allow a malicious or faulty USB device to cause a system crash or potentially execute unauthorized code. By sending specially crafted messages during the device discovery process, a connected USB partner can overflow internal memory buffers. This issue primarily affects systems where untrusted USB devices can be physically connected.

Technical details

A buffer overflow exists in the svdm_consume_modes() function within drivers/usb/typec/tcpm/tcpm.c. The function originally performed a bounds check on the altmode_desc array only once before entering a processing loop, rather than validating the index during each iteration. A malicious USB partner can exploit this by sending an unsolicited Discover Modes ACK containing more Vendor Defined Objects (VDOs) than the array can hold, leading to an out-of-bounds write into adjacent fields of the tcpm_port structure, such as the partner_altmode pointer array. The fix moves the bounds check inside the loop to ensure the index never exceeds ALTMODE_DISCOVERY_MAX.

Affected products

  • Linux Linux Kernel 6.12.93, 6.18.35, 7.0.12

Timeline

  • 2026-05-13: patched: Initial fix authored by Greg Kroah-Hartman
  • 2026-07-19: disclosed: CVE-2026-63962 published

References

Related threats