HomeDefectsLIN1025-16988
Acknowledged

LIN1025-16988 : Security Advisory - linux - CVE-2026-63958

Created: Aug 1, 2026    Updated: Aug 11, 2026
Found In Version: 10.25.33.2
Severity: Standard
Applicable for: Wind River Linux LTS 25
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:  usb: typec: ucsi: validate connector number in ucsi_connector_change()  The connector number in a UCSI CCI notification is a 7-bit field supplied by the PPM.  ucsi_connector_change() uses it to index the ucsi->connector[] array without checking it against the number of connectors the PPM reported at init time, so a buggy or malicious PPM (EC firmware, or an I2C-attached UCSI controller on the ccg / stm32g0 / glink transports) can drive schedule_work() on memory past the end of the array.  Reject connector numbers that are zero or exceed cap.num_connectors before dereferencing the array.