VYPR
Unrated severityNVD Advisory· Published Jul 19, 2026· Updated Jul 27, 2026

CVE-2026-63899

CVE-2026-63899

Description

In the Linux kernel, the following vulnerability has been resolved:

USB: serial: mxuport: fix memory corruption with small endpoint

Make sure that the bulk-out endpoint max packet size is at least eight bytes to avoid user-controlled slab corruption should a malicious device report a smaller size.

Affected products

15

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.