In the Linux kernel, the following vulnerability has been resolved:
USB: serial: mxuport: fix memory corruption with small endpoint
Make sure that the bulk-out endpoint max packet size is at least eight
bytes to avoid user-controlled slab corruption should a malicious device
report a smaller size.
Metrics
Affected Vendors & Products
References
History
Wed, 22 Jul 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-120 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Sun, 19 Jul 2026 15:30:00 +0000
Status: PUBLISHED
Assigner: Linux
Published: 2026-07-19T14:55:08.116Z
Updated: 2026-07-19T14:55:08.116Z
Reserved: 2026-07-19T07:54:57.019Z
Link: CVE-2026-63899
No data.
Status : Awaiting Analysis
Published: 2026-07-19T16:17:07.497
Modified: 2026-07-27T17:44:23.777
Link: CVE-2026-63899