{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "4ab8c18d4d67321cc7b660559de17511d4fc0237"
            },
            {
              "fixed": "845598b154b9a92e9d279fafafa9405c121ae805"
            },
            {
              "fixed": "4505f33dab56c274e82f47f94bf60a8cbf8f4b42"
            },
            {
              "fixed": "cbad85b446c06adbc5e5bed565871bb918ce9d32"
            },
            {
              "fixed": "3389c149c68c3fea61910ad5d34f7bf3bff44e32"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Linux",
        "name": "Kernel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "4.19.0"
            },
            {
              "fixed": "6.12.93"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.13.0"
            },
            {
              "fixed": "6.18.35"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.19.0"
            },
            {
              "fixed": "7.0.12"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63962.json"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: tcpm: bound altmode_desc[] per iteration in svdm_consume_modes()\n\nsvdm_consume_modes() checks pmdata-\u003ealtmodes against the array size once\nbefore the loop over the count, but forgot to check the bound at every\npoint in the loop.\n\nIn the well-behaved SVDM discovery flow this is harmless because each of\nat most SVID_DISCOVERY_MAX SVIDs contributes at most MODE_DISCOVERY_MAX\nmodes, exactly filling altmode_desc[ALTMODE_DISCOVERY_MAX].  But the\nCMDT_RSP_ACK handler in tcpm_pd_svdm() does not correlate an incoming\nACK with any request the port actually sent.  Once port-\u003epartner is set,\nan unsolicited Discover Modes ACK is consumed unconditionally.  A broken\nor malicious port partner can therefore drive altmodes to\nALTMODE_DISCOVERY_MAX - 1 via the normal flow, and then send one extra\nDiscover Modes ACK with seven VDOs.  Because the pre-loop check passes,\nthe loop could then writes up to five entries past altmode_desc[].  For\nmode_data_prime the next field in struct tcpm_port is the\npartner_altmode[] pointer array, which then receives partner-chosen\nSVID/VDO bytes.\n\nMove the bound check inside the loop so the array can never be indexed\npast ALTMODE_DISCOVERY_MAX regardless of how many VDOs the partner\nsupplies or how the function was reached.",
  "id": "CVE-2026-63962",
  "modified": "2026-07-22T05:30:03.018426841Z",
  "published": "2026-07-19T14:55:51.682Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/3389c149c68c3fea61910ad5d34f7bf3bff44e32"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/4505f33dab56c274e82f47f94bf60a8cbf8f4b42"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/845598b154b9a92e9d279fafafa9405c121ae805"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/cbad85b446c06adbc5e5bed565871bb918ce9d32"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63962.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63962"
    },
    {
      "type": "PACKAGE",
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"
    }
  ],
  "schema_version": "1.8.0",
  "summary": "usb: typec: tcpm: bound altmode_desc[] per iteration in svdm_consume_modes()"
}