{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.1.176-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.94-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.0.12-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  thunderbolt: property: Reject dir_len \u003c 4 to prevent size_t underflow  On the non-root path, __tb_property_parse_dir() takes dir_len from entry-\u003elength (u16 widened to size_t).  Two distinct OOB conditions follow when entry-\u003elength \u003c 4:  1. The non-root path begins with kmemdup(\u0026block[dir_offset],    sizeof(*dir-\u003euuid), ...) which always reads 4 dwords from    dir_offset.  tb_property_entry_valid() only enforces    dir_offset + entry-\u003elength \u003c= block_len, so a crafted entry    with dir_offset close to the end of the property block and    entry-\u003elength in 0..3 passes that gate but lets the UUID copy    run off the block (e.g. dir_offset = 497, dir_len = 3 in a    500-dword block reads block[497..501]).  2. After the kmemdup, content_len = dir_len - 4 underflows size_t    to ~SIZE_MAX, nentries becomes SIZE_MAX / 4, and the entry    walk runs OOB on each iteration until an entry fails    validation or the kernel oopses on an unmapped page.  Reject dir_len \u003c 4 on the non-root path *before* the UUID kmemdup, which closes both holes.  Also move INIT_LIST_HEAD(\u0026dir-\u003eproperties) up to immediately after the dir allocation so the new error-return path (and the existing uuid-alloc failure path) calling tb_property_free_dir() sees a walkable list rather than the zero-initialized NULL next/prev that list_for_each_entry_safe() would oops on.",
  "id": "DEBIAN-CVE-2026-63892",
  "modified": "2026-09-14T16:47:35.895475754Z",
  "published": "2026-07-19T16:17:06.577Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-63892"
    }
  ],
  "upstream": [
    "CVE-2026-63892"
  ]
}