CVE-2026-63892
Last modified
CVE-2026-63892 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow On the non-root path, __tb_property_parse_dir() takes dir_len from entry->length (u16 widened to size_t). Two distinct OOB conditions follow when entry->length < 4: 1. EPSS estimates a 0.22% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow On the non-root path, __tb_property_parse_dir() takes dir_len from entry->length (u16 widened to size_t). Two distinct OOB conditions follow when entry->length < 4: 1. The non-root path begins with kmemdup(&block[dir_offset], sizeof(*dir->uuid), ...) which always reads 4 dwords from dir_offset. tb_property_entry_valid() only enforces dir_offset + entry->length <= block_len, so a crafted entry with dir_offset close to the end of the property block and entry->length in 0..3 passes that gate but lets the UUID copy run off the block (e.g. dir_offset = 497, dir_len = 3 in a 500-dword block reads block[497..501]). 2. After the kmemdup, content_len = dir_len - 4 underflows size_t to ~SIZE_MAX, nentries becomes SIZE_MAX / 4, and the entry walk runs OOB on each iteration until an entry fails validation or the kernel oopses on an unmapped page. Reject dir_len < 4 on the non-root path *before* the UUID kmemdup, which closes both holes. Also move INIT_LIST_HEAD(&dir->properties) up to immediately after the dir allocation so the new error-return path (and the existing uuid-alloc failure path) calling tb_property_free_dir() sees a walkable list rather than the zero-initialized NULL next/prev that list_for_each_entry_safe() would oops on.
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= cdae7c07e3e3509eaabc18c1640a55dc5b99c179, < 37abc4504fa19d8f9f1e87792e8a2b8fdb308e40; >= cdae7c07e3e3509eaabc18c1640a55dc5b99c179, < e2d4d51cf5785815fa4e91e0c019e3eb2506a84c; >= cdae7c07e3e3509eaabc18c1640a55dc5b99c179, < de618299190b418291609e6921557253bd417e25; >= cdae7c07e3e3509eaabc18c1640a55dc5b99c179, < 5506c825f14d810f0690b1f4367cb7249ebb387a; >= cdae7c07e3e3509eaabc18c1640a55dc5b99c179, < 542a13890b742099c461d70920e97b14e568f6ec; >= cdae7c07e3e3509eaabc18c1640a55dc5b99c179, < d548179adcc87e1bc66b17e00352a1f536e76065; >= cdae7c07e3e3509eaabc18c1640a55dc5b99c179, < 3bec49ca55e08fb085cc4318f24b1b37eaab28cb; >= cdae7c07e3e3509eaabc18c1640a55dc5b99c179, < de21b59c29e31c5108ddc04210631bbfab81b997 |
| Linux | Linux | 4.15 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-63892?
How severe is CVE-2026-63892?
How do I fix CVE-2026-63892?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-63887In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-63888In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-63889In the Linux kernel, the following vulnerability has been re…8.1
- CVE-2026-6389IBM Turbonomic prometurbo agent 8.16.0 through 8.17.6 IBM Tu…7.8
- CVE-2026-63890In the Linux kernel, the following vulnerability has been re…
- CVE-2026-63891In the Linux kernel, the following vulnerability has been re…
- CVE-2026-63893In the Linux kernel, the following vulnerability has been re…8.1
- CVE-2026-63894In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-63895In the Linux kernel, the following vulnerability has been re…
- CVE-2026-63896In the Linux kernel, the following vulnerability has been re…
- CVE-2026-63897In the Linux kernel, the following vulnerability has been re…
- CVE-2026-63898In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-63892?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
