CVE-2026-63928
N/AIn the Linux kernel, the following vulnerability has been resolved: USB: serial: omninet: fix memory corruption with small endpoint Make sure that the bulk-out buffers are at least as large as the hardcoded transfer size to avoid user-controlled slab corruption should a malicious device report a smaller endpoint max packet size than expected.
NO EXPLOITATION SIGNALS
No known exploitation, public exploit, or elevated probability at this time. Track for changes.
Exploitation likelihood
0.2%chance of exploitation in 30 days · 11th percentile
○ In CISA KEV
○ Public exploit / PoC
Impact if exploited
—CVSS · not scored
- No impact metrics
Proof of concept & exploit code
- github-search Search GitHub for public PoC repos
Test against your own equipment
curl -s https://vulnpedia.com/cve/CVE-2026-63928/poc.jsonMachine-readable PoC index for this CVE (for automation).Listed for defensive triage, patch verification, and authorized testing on systems you own. Machine-readable: /cve/CVE-2026-63928/poc.json
References
Technical & other
- https://git.kernel.org/stable/c/180996f0ca774001944e4afa452d569ba2f6455c
- https://git.kernel.org/stable/c/b496e25ead5976bce2891dacaed09beb53a54f9f
- https://git.kernel.org/stable/c/4e7d32189d6219beb7db37cd0ea36b6bac7dfedb
- https://git.kernel.org/stable/c/9a3860454bdfb765f936965e975c594352602ffc
- https://git.kernel.org/stable/c/0bda1893e4cc4ad2b7dcdbaca246f2af688c6c2a
- https://git.kernel.org/stable/c/0fee0ccac29e088d4bfab7e2d075725dcecd803d
- https://git.kernel.org/stable/c/f34cf2928387fba01a78381f3258c7e1428897d9
- https://git.kernel.org/stable/c/60df93d30f9bdd27db17c4d80ed80ef718d7226b