PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-63899 Linux CVE debrief

A vulnerability in the Linux kernel's USB: serial: mxuport functionality has been resolved. The vulnerability could allow user-controlled slab corruption if a malicious device reports a smaller size. The fix ensures that the bulk-out endpoint max packet size is at least eight bytes. This vulnerability affects users of the Linux kernel with USB: serial: mxuport functionality. The vulnerability has a medium defensive priority.

Vendor
Linux
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-19
Original CVE updated
2026-07-27
Advisory published
2026-07-19
Advisory updated
2026-07-27

Who should care

Users of Linux kernel with USB: serial: mxuport functionality, Linux kernel maintainers, and security teams responsible for vulnerability management should be aware of this vulnerability. They should review the official advisory and apply the patch or implement mitigations as necessary.

Technical summary

The Linux kernel has a vulnerability in the USB: serial: mxuport functionality. The vulnerability could allow user-controlled slab corruption if a malicious device reports a smaller size. The fix ensures that the bulk-out endpoint max packet size is at least eight bytes to prevent the corruption. Users of the Linux kernel with USB: serial: mxuport functionality should verify and apply the kernel patch, monitor for malicious devices, and implement compensating controls.

Defensive priority

Medium

Recommended defensive actions

  • Verify and apply the kernel patch
  • Monitor for malicious devices
  • Implement compensating controls
  • Review the official advisory
  • Perform vulnerability scanning
  • Inventory affected systems
  • Track patch deployment

Evidence notes

The CVE record was published on 2026-07-19T16:17:07.497Z and has not been modified since then. The NVD entry is currently Received. There is limited information available about the vulnerability, and defenders should verify the affected scope and severity with the official advisory. The vulnerability affects the Linux kernel's USB: serial: mxuport functionality. The fix ensures that the bulk-out endpoint max packet size is at least eight bytes to avoid user-controlled slab corruption. Evidence is limited to CVE and NVD details.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-63899 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-63899

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-63899 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-63899

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/086b858b5f5125bc9d967ea2bd825f83d9f8f29d

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/2f3661eb2446e1ef593da45e01a3b21a906768ec

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/4085f0dbb1ce2251c9a5938d693de6593f0ab2bd

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/6c0cf56f00f280d72180bb6ce79741bc787a6269

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/b40166b4ef96067620a0f248e74ad9658c8f680c

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/be3a1ed4ae51fa8dde57383277d336ce834f2cd9

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/ccbec56f2f9af008f1574335cc6a668f16603e47

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.