CVE-2026-63956

UnknownEPSS 0.21%

Last modified

CVE-2026-63956 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: USB: serial: cypress_m8: fix memory corruption with small endpoint Make sure that the interrupt-out endpoint max packet size is at least eight bytes to avoid user-controlled slab corruption or NULL-pointer dereference should a malicious device report a smaller size.. EPSS estimates a 0.21% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: USB: serial: cypress_m8: fix memory corruption with small endpoint Make sure that the interrupt-out endpoint max packet size is at least eight bytes to avoid user-controlled slab corruption or NULL-pointer dereference should a malicious device report a smaller size.

Metrics

EPSS Probability
0.21%

11.5th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 3416eaa1f8f8d516b77de514e14cf8da256d28fb, < 4fcb22218f0a7229b7ce3b3952fb644def293fa5; >= 3416eaa1f8f8d516b77de514e14cf8da256d28fb, < ad3d1628a46134276546d7a12fedf04be9979158; >= 3416eaa1f8f8d516b77de514e14cf8da256d28fb, < 52e18ae0c47c5c89e18fcd8022f287f7cc8802ec; >= 3416eaa1f8f8d516b77de514e14cf8da256d28fb, < 4bcaa59f403dbde6328604a500d65ee8d40975d9; >= 3416eaa1f8f8d516b77de514e14cf8da256d28fb, < 1ef25704bd3b625fd151c09feee459479f71ee64; >= 3416eaa1f8f8d516b77de514e14cf8da256d28fb, < 284105c40fc31fff90cdab8a0377aaeb92f87f0e; >= 3416eaa1f8f8d516b77de514e14cf8da256d28fb, < 6c13f3bb652bc8665e709ba07122612586aea648; >= 3416eaa1f8f8d516b77de514e14cf8da256d28fb, < e1a9d791fd66ab2431b9e6f6f835823809869047
LinuxLinux2.6.26

References

Timeline

Published
Last Modified
Status
Awaiting Analysis

Frequently Asked Questions

What is CVE-2026-63956?
In the Linux kernel, the following vulnerability has been resolved: USB: serial: cypress_m8: fix memory corruption with small endpoint Make sure that the interrupt-out endpoint max packet size is at least eight bytes to avoid user-controlled slab corruption or NULL-pointer dereference should a malicious device report a smaller size.
How severe is CVE-2026-63956?
Severity scoring for CVE-2026-63956 is pending analysis. The EPSS model estimates a 0.21% probability of exploitation in the next 30 days.
How do I fix CVE-2026-63956?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-63956?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST