CVE-2026-63956
Published Jul 19, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: USB: serial: cypress_m8: fix memory corruption with small endpoint Make sure that the interrupt-out endpoint max packet size is at least eight bytes to avoid user-controlled slab corruption or NULL-pointer dereference should a malicious device report a smaller size.
Is your site exposed to CVE-2026-63956?
Run a free security scan — no signup, results in seconds.
References
Other References
https://git.kernel.org/stable/c/1ef25704bd3b625fd151c09feee459479f71ee64
https://git.kernel.org/stable/c/284105c40fc31fff90cdab8a0377aaeb92f87f0e
https://git.kernel.org/stable/c/4bcaa59f403dbde6328604a500d65ee8d40975d9
https://git.kernel.org/stable/c/4fcb22218f0a7229b7ce3b3952fb644def293fa5
https://git.kernel.org/stable/c/52e18ae0c47c5c89e18fcd8022f287f7cc8802ec
https://git.kernel.org/stable/c/6c13f3bb652bc8665e709ba07122612586aea648
https://git.kernel.org/stable/c/ad3d1628a46134276546d7a12fedf04be9979158
https://git.kernel.org/stable/c/e1a9d791fd66ab2431b9e6f6f835823809869047
Frequently Asked Questions
What is CVE-2026-63956? +
In the Linux kernel, the following vulnerability has been resolved:
USB: serial: cypress_m8: fix memory corruption with small endpoint
Make sure that the interrupt-out endpoint max packet size is at least
eight bytes to avoid user-controlled slab corruption or NULL-pointer
dereference should a malicious device report a smaller size.
How do I check if I'm vulnerable to CVE-2026-63956? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.