CVE-2026-63963
In the Linux kernel, the following vulnerability has been resolved: usb: typec: tcpm: validate VDO count in Discover Identity ACK handlers Properly validate the count passed from a device when calling svdm_consume_identity() or svdm_consume_identity_sop_prime() as the device-controlled value could index off of the static arrays, which could leak data.
Affected versions
Fixed in
6.12.93,
6.18.35,
7.0.12,
7.1
and their respective stable series.
References
4 totalFrequently asked questions
-
What is CVE-2026-63963?
CVE-2026-63963 is a unscored severity Linux kernel vulnerability . CVE-2026-63963 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.
-
Is there a patch available for CVE-2026-63963?
Yes — CVE-2026-63963 has been patched. Fixed versions include 6.12.93, 6.18.35, 7.0.12 and others.
-
Is CVE-2026-63963 actively exploited?
No — CVE-2026-63963 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.