Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.2%top 89%

In the Linux kernel, the following vulnerability has been resolved: USB: serial: cypress_m8: validate interrupt packet headers… (CVE-2026-63902)

0
Medium
Published: 07/19/2026 (07/19/2026, 18:31:45 UTC)
Source: GCVE Database

Description

A vulnerability in the Linux kernel's USB serial driver for Cypress M8 devices was resolved by validating interrupt packet headers. The issue involved improper parsing of interrupt-in buffers that could lead to out-of-bounds reads when malformed short reports were processed. The fix ensures that only packets with valid headers are read, ignoring malformed packets and resubmitting the interrupt URB to prevent memory errors.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/19/2026, 20:10:46 UTC

Technical Analysis

The Linux kernel's cypress_m8 USB serial driver had a vulnerability in the cypress_read_int_callback() function where interrupt-in buffers were parsed without sufficient validation of the packet headers. Format 1 packets have a two-byte status/count header, and format 2 packets have a one-byte combined header. The usb-serial core sizes the buffer based on the endpoint descriptor's wMaxPacketSize, but successful interrupt transfers could complete short if URB_SHORT_NOT_OK was not set, leading to potential out-of-bounds reads. The patch added checks to verify the presence of the expected header before reading, ignoring malformed short reports and resubmitting the interrupt URB to avoid slab-out-of-bounds errors detected by KASAN.

Potential Impact

This vulnerability could cause out-of-bounds memory reads in the kernel when processing malformed USB interrupt packets from Cypress M8 serial devices. Such memory errors can lead to kernel instability or crashes. There is no indication of known exploits in the wild or direct privilege escalation or code execution impact from the provided data.

Mitigation Recommendations

A fix has been applied in the Linux kernel to validate interrupt packet headers in the cypress_m8 USB serial driver, preventing out-of-bounds reads. Users should update to a Linux kernel version that includes this patch. Since no specific patched versions are provided, check the vendor or kernel mailing lists for the exact fixed version. No additional mitigation is indicated.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-28gg-7x4r-8gcw
Osv Schema Version
1.4.0
Aliases
["CVE-2026-63902"]
Ecosystems
[]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a5d27ab2a4a8d598912fc45

Added to database: 07/19/2026, 19:38:19 UTC

Last enriched: 07/19/2026, 20:10:46 UTC

Last updated: 07/20/2026, 17:26:47 UTC

Views: 11

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses