HomeDefectsLIN1025-16991
Acknowledged

LIN1025-16991 : Security Advisory - linux - CVE-2026-63961

Created: Aug 1, 2026    Updated: Aug 11, 2026
Found In Version: 10.25.33.2
Severity: Standard
Applicable for: Wind River Linux LTS 25
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:  usb: typec: altmodes/displayport: validate count before reading Status Update VDO  A broken/malicious device can send the incorrect count for a status update VDO, which will cause the kernel to read uninitialized stack data and send it off elsewhere.  Fix this up by correctly verifying the count for the update object.