NONE · 0

CVE-2026-63956

In the Linux kernel, the following vulnerability has been resolved: USB: serial: cypress_m8: fix memory corruption with small endpoint Make sure that the interrupt-out endpoint max packet size is at...

Vulnerability Description

In the Linux kernel, the following vulnerability has been resolved: USB: serial: cypress_m8: fix memory corruption with small endpoint Make sure that the interrupt-out endpoint max packet size is at least eight bytes to avoid user-controlled slab corruption or NULL-pointer dereference should a malicious device report a smaller size.

References

FAQ

What is CVE-2026-63956?

CVE-2026-63956 is a documented vulnerability. In the Linux kernel, the following vulnerability has been resolved: USB: serial: cypress_m8: fix memory corruption with small endpoint Make sure that the interrupt-out endpoint max packet size is at...

How severe is CVE-2026-63956?

CVSS scoring is not yet available for CVE-2026-63956. Check NVD for updates.

Is there a patch for CVE-2026-63956?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.