CVE-2026-63899

UnknownEPSS 0.21%

Last modified

CVE-2026-63899 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: USB: serial: mxuport: fix memory corruption with small endpoint Make sure that the bulk-out endpoint max packet size is at least eight bytes to avoid user-controlled slab corruption should a malicious device report a smaller size.. EPSS estimates a 0.21% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: USB: serial: mxuport: fix memory corruption with small endpoint Make sure that the bulk-out endpoint max packet size is at least eight bytes to avoid user-controlled slab corruption should a malicious device report a smaller size.

Metrics

EPSS Probability
0.21%

11.4th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= ee467a1f2066d2bfa293f7c2c7f1ff7000b0a39e, < 086b858b5f5125bc9d967ea2bd825f83d9f8f29d; >= ee467a1f2066d2bfa293f7c2c7f1ff7000b0a39e, < 2f3661eb2446e1ef593da45e01a3b21a906768ec; >= ee467a1f2066d2bfa293f7c2c7f1ff7000b0a39e, < ccbec56f2f9af008f1574335cc6a668f16603e47; >= ee467a1f2066d2bfa293f7c2c7f1ff7000b0a39e, < be3a1ed4ae51fa8dde57383277d336ce834f2cd9; >= ee467a1f2066d2bfa293f7c2c7f1ff7000b0a39e, < e906545641d34fb1a09a65b4b5cfdff40eb09681; >= ee467a1f2066d2bfa293f7c2c7f1ff7000b0a39e, < 6c0cf56f00f280d72180bb6ce79741bc787a6269; >= ee467a1f2066d2bfa293f7c2c7f1ff7000b0a39e, < b40166b4ef96067620a0f248e74ad9658c8f680c; >= ee467a1f2066d2bfa293f7c2c7f1ff7000b0a39e, < 4085f0dbb1ce2251c9a5938d693de6593f0ab2bd
LinuxLinux3.14

References

Timeline

Published
Last Modified
Status
Awaiting Analysis

Frequently Asked Questions

What is CVE-2026-63899?
In the Linux kernel, the following vulnerability has been resolved: USB: serial: mxuport: fix memory corruption with small endpoint Make sure that the bulk-out endpoint max packet size is at least eight bytes to avoid user-controlled slab corruption should a malicious device report a smaller size.
How severe is CVE-2026-63899?
Severity scoring for CVE-2026-63899 is pending analysis. The EPSS model estimates a 0.21% probability of exploitation in the next 30 days.
How do I fix CVE-2026-63899?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-63899?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST