CVE-2026-63904
N/AIn the Linux kernel, the following vulnerability has been resolved: usb: usbtmc: check URB actual_length for interrupt-IN notifications USBTMC devices can use an optional interrupt endpoint for notification messages. These typically contain two-byte headers indicating the payload format, but the driver does not check if these headers are present before accessing the data buffers. In cases where the URB actual_length is not enough to fit these headers, the driver will either cause an out-of-bounds read, or consume stale leftover data from a previous notification. Fix by checking if actual_data contains enough bytes for the headers, otherwise resubmit URB to the interrupt endpoint.
No known exploitation, public exploit, or elevated probability at this time. Track for changes.
Exploitation likelihood
0.2%chance of exploitation in 30 days · 11th percentile
Impact if exploited
—CVSS · not scored
- No impact metrics
Proof of concept & exploit code
- github-search Search GitHub for public PoC repos
Test against your own equipment
curl -s https://vulnpedia.com/cve/CVE-2026-63904/poc.jsonMachine-readable PoC index for this CVE (for automation).Listed for defensive triage, patch verification, and authorized testing on systems you own. Machine-readable: /cve/CVE-2026-63904/poc.json
References
Technical & other
- https://git.kernel.org/stable/c/e794bd67b3faf98af46f958897f6b91412c7d2a9
- https://git.kernel.org/stable/c/e3eec3005de44e7f37d8d7724be636446516ab42
- https://git.kernel.org/stable/c/ae87f505917e703ae3b487d9663d78826ff43608
- https://git.kernel.org/stable/c/5de7df75ef3a2756b25fe3d582a4a2970444fe5a
- https://git.kernel.org/stable/c/69020fa089f1bf0e1a10a15265f31b143a846409
- https://git.kernel.org/stable/c/75f6d3da2cc646983f41807ef98851569c12bca9
- https://git.kernel.org/stable/c/f141b01eaa58ac7e323931d670318aa247bff087
- https://git.kernel.org/stable/c/52f2ad3f7e5eb3b5908e1d685d4342519dc9cfcd