CVE-2026-63928
Published Jul 19, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: USB: serial: omninet: fix memory corruption with small endpoint Make sure that the bulk-out buffers are at least as large as the hardcoded transfer size to avoid user-controlled slab corruption should a malicious device report a smaller endpoint max packet size than expected.
Is your site exposed to CVE-2026-63928?
Run a free security scan — no signup, results in seconds.
References
Other References
https://git.kernel.org/stable/c/0bda1893e4cc4ad2b7dcdbaca246f2af688c6c2a
https://git.kernel.org/stable/c/0fee0ccac29e088d4bfab7e2d075725dcecd803d
https://git.kernel.org/stable/c/180996f0ca774001944e4afa452d569ba2f6455c
https://git.kernel.org/stable/c/4e7d32189d6219beb7db37cd0ea36b6bac7dfedb
https://git.kernel.org/stable/c/60df93d30f9bdd27db17c4d80ed80ef718d7226b
https://git.kernel.org/stable/c/9a3860454bdfb765f936965e975c594352602ffc
https://git.kernel.org/stable/c/b496e25ead5976bce2891dacaed09beb53a54f9f
https://git.kernel.org/stable/c/f34cf2928387fba01a78381f3258c7e1428897d9
Frequently Asked Questions
What is CVE-2026-63928? +
In the Linux kernel, the following vulnerability has been resolved:
USB: serial: omninet: fix memory corruption with small endpoint
Make sure that the bulk-out buffers are at least as large as the
hardcoded transfer size to avoid user-controlled slab corruption should
a malicious device report a smaller endpoint max packet size than
expected.
How do I check if I'm vulnerable to CVE-2026-63928? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.