{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "5c9ae5a87573d38cfc4c740aafda2fa6ce06e401"
            },
            {
              "fixed": "b41dfc033fe594e152648050e95b9489cd53e9e3"
            },
            {
              "fixed": "2f395ca1263bd181995eb829f5943a83a20db213"
            },
            {
              "fixed": "6526f8684f72391138353642af908803ba70795e"
            },
            {
              "fixed": "3f432b8203066c26770fe6ea591361f10021dd6b"
            },
            {
              "fixed": "c4ee519b06389e59ba2d6aa722fcc4a02a8bbcbb"
            },
            {
              "fixed": "a38ed87818b2419090fb1a6338ddce6842b65dfa"
            },
            {
              "fixed": "c8460de584fe5415d212cfdd127d4db90835a450"
            },
            {
              "fixed": "d7486952bf74e546ee3748fb14b2d07881fa6273"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Linux",
        "name": "Kernel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "5.2.0"
            },
            {
              "fixed": "5.10.259"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "5.11.0"
            },
            {
              "fixed": "5.15.210"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "5.16.0"
            },
            {
              "fixed": "6.1.176"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.2.0"
            },
            {
              "fixed": "6.6.143"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.7.0"
            },
            {
              "fixed": "6.12.93"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.13.0"
            },
            {
              "fixed": "6.18.35"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.19.0"
            },
            {
              "fixed": "7.0.12"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63964.json"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: ucsi: ccg: reject firmware images without a ':' record header\n\ndo_flash() locates the first .cyacd record with\n\n\tp = strnchr(fw-\u003edata, fw-\u003esize, ':');\n\twhile (p \u003c eof) {\n\t\ts = strnchr(p + 1, eof - p - 1, ':');\n\t\t...\n\t}\n\nIf the firmware image contains no ':' byte,  strnchr() returns NULL.\nNULL compares less than the valid kernel pointer eof, so the loop body\nruns and strnchr() is called with p + 1 == (void *)1 and a length of\nroughly (unsigned long)eof, causing a wonderful crash.\n\nThe not_signed_fw fallthrough earlier in do_flash() and the chip-state\nbranches in ccg_fw_update_needed() allow an unsigned blob to reach this\nloop, so a root user who can place a crafted file under /lib/firmware\nand write the do_flash sysfs attribute can trigger the oops.\n\nBail out with -EINVAL when the initial strnchr() returns NULL.",
  "id": "CVE-2026-63964",
  "modified": "2026-08-12T03:51:42.502082663Z",
  "published": "2026-07-19T14:55:53.115Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/2f395ca1263bd181995eb829f5943a83a20db213"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/3f432b8203066c26770fe6ea591361f10021dd6b"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/6526f8684f72391138353642af908803ba70795e"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/a38ed87818b2419090fb1a6338ddce6842b65dfa"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/b41dfc033fe594e152648050e95b9489cd53e9e3"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/c4ee519b06389e59ba2d6aa722fcc4a02a8bbcbb"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/c8460de584fe5415d212cfdd127d4db90835a450"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/d7486952bf74e546ee3748fb14b2d07881fa6273"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63964.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63964"
    },
    {
      "type": "PACKAGE",
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"
    }
  ],
  "schema_version": "1.9.0",
  "summary": "usb: typec: ucsi: ccg: reject firmware images without a ':' record header"
}