{"schema_version":"1.9.0","id":"CVE-2026-63904","published":"2026-07-19T14:55:11.547Z","modified":"2026-08-31T18:26:06.929411728Z","related":["SUSE-SU-2026:23066-1","SUSE-SU-2026:23068-1","SUSE-SU-2026:23193-1","SUSE-SU-2026:23194-1","SUSE-SU-2026:23221-1","SUSE-SU-2026:23231-1","SUSE-SU-2026:23237-1","SUSE-SU-2026:23241-1","SUSE-SU-2026:23244-1","SUSE-SU-2026:3790-1","SUSE-SU-2026:3810-1","openSUSE-SU-2026:21555-1"],"summary":"usb: usbtmc: check URB actual_length for interrupt-IN notifications","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: usbtmc: check URB actual_length for interrupt-IN notifications\n\nUSBTMC devices can use an optional interrupt endpoint for notification\nmessages. These typically contain two-byte headers indicating the\npayload format, but the driver does not check if these headers are\npresent before accessing the data buffers. In cases where the URB\nactual_length is not enough to fit these headers, the driver will either\ncause an out-of-bounds read, or consume stale leftover data from a\nprevious notification.\n\nFix by checking if actual_data contains enough bytes for the headers,\notherwise resubmit URB to the interrupt endpoint.","affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"dbf3e7f654c0f06a932b8fcafac78de9d0b81d68"},{"fixed":"e794bd67b3faf98af46f958897f6b91412c7d2a9"},{"fixed":"e3eec3005de44e7f37d8d7724be636446516ab42"},{"fixed":"ae87f505917e703ae3b487d9663d78826ff43608"},{"fixed":"5de7df75ef3a2756b25fe3d582a4a2970444fe5a"},{"fixed":"69020fa089f1bf0e1a10a15265f31b143a846409"},{"fixed":"75f6d3da2cc646983f41807ef98851569c12bca9"},{"fixed":"f141b01eaa58ac7e323931d670318aa247bff087"},{"fixed":"52f2ad3f7e5eb3b5908e1d685d4342519dc9cfcd"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63904.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.6.0"},{"fixed":"5.10.259"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.210"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.176"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.143"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.93"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.35"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.0.12"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63904.json"}}],"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/52f2ad3f7e5eb3b5908e1d685d4342519dc9cfcd"},{"type":"WEB","url":"https://git.kernel.org/stable/c/5de7df75ef3a2756b25fe3d582a4a2970444fe5a"},{"type":"WEB","url":"https://git.kernel.org/stable/c/69020fa089f1bf0e1a10a15265f31b143a846409"},{"type":"WEB","url":"https://git.kernel.org/stable/c/75f6d3da2cc646983f41807ef98851569c12bca9"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ae87f505917e703ae3b487d9663d78826ff43608"},{"type":"WEB","url":"https://git.kernel.org/stable/c/e3eec3005de44e7f37d8d7724be636446516ab42"},{"type":"WEB","url":"https://git.kernel.org/stable/c/e794bd67b3faf98af46f958897f6b91412c7d2a9"},{"type":"WEB","url":"https://git.kernel.org/stable/c/f141b01eaa58ac7e323931d670318aa247bff087"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63904.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63904"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63904.json"}}