CVE-2026-63959
Published Jul 19, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT A broken/malicious port can transmit a CRC-valid frame whose header advertises up to seven data objects but whose body carries fewer than that. Check for this, and rightfully reject the message, instead of reading from uninitialized stack memory.
Is your site exposed to CVE-2026-63959?
Run a free security scan — no signup, results in seconds.
References
Other References
https://git.kernel.org/stable/c/0af00f1459f5dd757f0d392f8caa38039561ac62
https://git.kernel.org/stable/c/9b496e3371c04f0a03b7faa5d2442536d00e3998
https://git.kernel.org/stable/c/aa2f716327be1818e1cb156da8a2844804aaec2f
https://git.kernel.org/stable/c/c4ab8e2d4432abb646c5c0687f8dab173da901f9
https://git.kernel.org/stable/c/dc17721d42e6d89f63572e63add8306a0e15eb3c
Frequently Asked Questions
What is CVE-2026-63959? +
In the Linux kernel, the following vulnerability has been resolved:
usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT
A broken/malicious port can transmit a CRC-valid frame whose header
advertises up to seven data objects but whose body carries fewer than
that. Check for this, and rightfully reject the message, instead of
reading from uninitialized stack memory.
How do I check if I'm vulnerable to CVE-2026-63959? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.