news.mlab.sh
Vulnerabilities
Vulnerability

CVE-2026-63928

Reference data from vuln.mlab.sh, coverage from our own index.

CVSS
7.0 High
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
0.22%
Risk score
8.4
Published
2026-07-19
Status
Published

In the Linux kernel, the following vulnerability has been resolved: USB: serial: omninet: fix memory corruption with small endpoint Make sure that the bulk-out buffers are at least as large as the hardcoded transfer size to avoid user-controlled slab corruption should a malicious device report a smaller endpoint max packet size than expected. A flaw was found in the Linux kernel's USB serial omninet driver. A malicious Universal Serial Bus (USB) device could exploit this by reporting a smaller maximum packet size than anticipated. This action would cause the system to allocate undersized data buffers, leading to memory corruption. Such corruption could allow an attacker to trigger a denial of service or potentially execute unauthorized code.

Weaknesses

CWE-787

Coverage 6

Advisories and references