CVE-2026-63898

UnknownEPSS 0.21%

Last modified

CVE-2026-63898 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: USB: serial: mct_u232: fix memory corruption with small endpoint The driver overrides the maximum transfer size for a specific device which only accepts 16 byte packets for its 32 byte bulk-out endpoint. Make sure to never increase the maximum transfer size to prevent slab corruption should a malicious device report a smaller endpoint max packet size than expected.. EPSS estimates a 0.21% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: USB: serial: mct_u232: fix memory corruption with small endpoint The driver overrides the maximum transfer size for a specific device which only accepts 16 byte packets for its 32 byte bulk-out endpoint. Make sure to never increase the maximum transfer size to prevent slab corruption should a malicious device report a smaller endpoint max packet size than expected.

Metrics

EPSS Probability
0.21%

11.4th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < 94edbbc5fe00d03cfe1d4e690d7d2cd36317a935; >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < bd2ddb3fe9052ad8703593bbec26ecc7ca92869e; >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < 39e295a91e80f3b91f61c7ada2bde434dcaba20d; >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < 90dbad14b109e5fdfb4934ff61e561d11ba3742d; >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < 6cb48f8890f9b2051d7c34823057296a536a31c5; >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < d8fdf33d6fcfb90cbec26299baf2352c84b2d768; >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < 57f332af1745014cd7e40414814ffaa6bc7d3b5b; >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < 915b36d701950503c4ea0f6e314b10868e59fce3
LinuxLinux2.6.12

References

Timeline

Published
Last Modified
Status
Awaiting Analysis

Frequently Asked Questions

What is CVE-2026-63898?
In the Linux kernel, the following vulnerability has been resolved: USB: serial: mct_u232: fix memory corruption with small endpoint The driver overrides the maximum transfer size for a specific device which only accepts 16 byte packets for its 32 byte bulk-out endpoint. Make sure to never increase the maximum transfer size to prevent slab corruption should a malicious device report a smaller endpoint max packet size than expected.
How severe is CVE-2026-63898?
Severity scoring for CVE-2026-63898 is pending analysis. The EPSS model estimates a 0.21% probability of exploitation in the next 30 days.
How do I fix CVE-2026-63898?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-63898?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST