CVE-2026-63899
Last modified
CVE-2026-63899 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: USB: serial: mxuport: fix memory corruption with small endpoint Make sure that the bulk-out endpoint max packet size is at least eight bytes to avoid user-controlled slab corruption should a malicious device report a smaller size.. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: USB: serial: mxuport: fix memory corruption with small endpoint Make sure that the bulk-out endpoint max packet size is at least eight bytes to avoid user-controlled slab corruption should a malicious device report a smaller size.
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= ee467a1f2066d2bfa293f7c2c7f1ff7000b0a39e, < 086b858b5f5125bc9d967ea2bd825f83d9f8f29d; >= ee467a1f2066d2bfa293f7c2c7f1ff7000b0a39e, < 2f3661eb2446e1ef593da45e01a3b21a906768ec; >= ee467a1f2066d2bfa293f7c2c7f1ff7000b0a39e, < ccbec56f2f9af008f1574335cc6a668f16603e47; >= ee467a1f2066d2bfa293f7c2c7f1ff7000b0a39e, < be3a1ed4ae51fa8dde57383277d336ce834f2cd9; >= ee467a1f2066d2bfa293f7c2c7f1ff7000b0a39e, < e906545641d34fb1a09a65b4b5cfdff40eb09681; >= ee467a1f2066d2bfa293f7c2c7f1ff7000b0a39e, < 6c0cf56f00f280d72180bb6ce79741bc787a6269; >= ee467a1f2066d2bfa293f7c2c7f1ff7000b0a39e, < b40166b4ef96067620a0f248e74ad9658c8f680c; >= ee467a1f2066d2bfa293f7c2c7f1ff7000b0a39e, < 4085f0dbb1ce2251c9a5938d693de6593f0ab2bd |
| Linux | Linux | 3.14 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-63899?
How severe is CVE-2026-63899?
How do I fix CVE-2026-63899?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-63893In the Linux kernel, the following vulnerability has been re…8.1
- CVE-2026-63894In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-63895In the Linux kernel, the following vulnerability has been re…
- CVE-2026-63896In the Linux kernel, the following vulnerability has been re…
- CVE-2026-63897In the Linux kernel, the following vulnerability has been re…
- CVE-2026-63898In the Linux kernel, the following vulnerability has been re…
- CVE-2026-6390A flaw was found in GNU nano's multi-buffer error message ha…6.8
- CVE-2026-63900In the Linux kernel, the following vulnerability has been re…
- CVE-2026-63901In the Linux kernel, the following vulnerability has been re…
- CVE-2026-63902In the Linux kernel, the following vulnerability has been re…
- CVE-2026-63903In the Linux kernel, the following vulnerability has been re…
- CVE-2026-63904In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-63899?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
