CVE-2026-63958

UnknownEPSS 0.21%

Last modified

CVE-2026-63958 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: validate connector number in ucsi_connector_change() The connector number in a UCSI CCI notification is a 7-bit field supplied by the PPM. ucsi_connector_change() uses it to index the ucsi->connector[] array without checking it against the number of connectors the PPM reported at init time, so a buggy or malicious PPM (EC firmware, or an I2C-attached UCSI controller on the ccg / stm32g0 / glink transports) can drive schedule_work() on memory past the end of the array. Reject connector numbers that are zero or exceed cap.num_connectors before dereferencing the array.. EPSS estimates a 0.21% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: validate connector number in ucsi_connector_change() The connector number in a UCSI CCI notification is a 7-bit field supplied by the PPM. ucsi_connector_change() uses it to index the ucsi->connector[] array without checking it against the number of connectors the PPM reported at init time, so a buggy or malicious PPM (EC firmware, or an I2C-attached UCSI controller on the ccg / stm32g0 / glink transports) can drive schedule_work() on memory past the end of the array. Reject connector numbers that are zero or exceed cap.num_connectors before dereferencing the array.

Metrics

EPSS Probability
0.21%

10.8th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= c1b0bc2dabfa884dea49c02adaf3cd6b52b33d2f, < cea949203faef9cb783adc7b978cce056271e057; >= c1b0bc2dabfa884dea49c02adaf3cd6b52b33d2f, < 156b6f0aec6108909b0c4aedc78865b12766b347; >= c1b0bc2dabfa884dea49c02adaf3cd6b52b33d2f, < bd24d92af4ae021b6209f28e9a57e1bf2260d4fd; >= c1b0bc2dabfa884dea49c02adaf3cd6b52b33d2f, < 0edd1e21587b0483c7ceb993b9fb9668bbef7433; >= c1b0bc2dabfa884dea49c02adaf3cd6b52b33d2f, < 5af2719b460ab904c504fc069d1dd2a3aa2b22b0; >= c1b0bc2dabfa884dea49c02adaf3cd6b52b33d2f, < 288a81a8507052bcfbf884d39a463c44c42c5fd9
LinuxLinux4.13

References

Timeline

Published
Last Modified
Status
Awaiting Analysis

Frequently Asked Questions

What is CVE-2026-63958?
In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: validate connector number in ucsi_connector_change() The connector number in a UCSI CCI notification is a 7-bit field supplied by the PPM. ucsi_connector_change() uses it to index the ucsi->connector[] array without checking it against the number of connectors the PPM reported at init time, so a buggy or malicious PPM (EC firmware, or an I2C-attached UCSI controller on the ccg / stm32g0 / glink transports) can drive schedule_work() on memory past the end of the array. Reject connector numbers that are zero or exceed cap.num_connectors before dereferencing the array.
How severe is CVE-2026-63958?
Severity scoring for CVE-2026-63958 is pending analysis. The EPSS model estimates a 0.21% probability of exploitation in the next 30 days.
How do I fix CVE-2026-63958?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-63958?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST