CVE-2026-63892
CVE CVE-2026-63892EUVD EUVD-2026-45665Veröffentlicht 2026-07-19T14:55:03.000Z
Was das Advisory beschreibt
In the Linux kernel, the following vulnerability has been resolved: thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow On the non-root path, __tb_property_parse_dir() takes dir_len from entry->length (u16 widened to size_t). Two distinct OOB conditions follow when entry->length < 4: 1. The non-root path begins with kmemdup(&block[dir_offset], sizeof(*dir->uuid), ...) which always reads 4 dwords from dir_offset. tb_property_entry_valid() only enforces dir_offset + entry->length <= block_len, so a crafted entry with dir_offset close to the end of the property block and entry->length in 0..3 passes that gate but lets the UUID copy run off the block (e.g. dir_offset = 497, dir_len = 3 in a 500-dword block reads block[497..501]). 2. After the kmemdup, content_len = dir_len - 4 underflows size_t to ~SIZE_MAX, nentries becomes SIZE_MAX / 4, and the entry walk runs OOB on each iteration until an entry fails validation or the kernel oopses on an unmapped page. Reject dir_len < 4 on the non-root path *before* the UUID kmemdup, which closes both holes. Also move INIT_LIST_HEAD(&dir->properties) up to immediately after the dir allocation so the new error-return path (and the existing uuid-alloc failure path) calling tb_property_free_dir() sees a walkable list rather than the zero-initialized NULL next/prev that list_for_each_entry_safe() would oops on.
Quelle: EUVD (ENISA), im Wortlaut der Meldung.
Produkte, die das Advisory nennt
Diese Angaben stammen aus der Meldung selbst, nicht aus einer Prüfung durch uns.
- Linux — Linux cdae7c07e3e3509eaabc18c1640a55dc5b99c179 <5506c825f14d810f0690b1f4367cb7249ebb387a; patch: 7.1; patch: 6.6.143; cdae7c07e3e3509eaabc18c1640a55dc5b99c179 <d548179adcc87e1bc66b17e00352a1f536e76065; patch: 6.12.93; patch: 6.18.35; patch: 0; cdae7c07e3e3509eaabc18c1640a55dc5b99c179 <de618299190b418291609e6921557253bd417e25; cdae7c07e3e3509eaabc18c1640a55dc5b99c179 <3bec49ca55e08fb085cc4318f24b1b37eaab28cb; cdae7c07e3e3509eaabc18c1640a55dc5b99c179 <de21b59c29e31c5108ddc04210631bbfab81b997; patch: 5.10.259; patch: 6.1.176; cdae7c07e3e3509eaabc18c1640a55dc5b99c179 <542a13890b742099c461d70920e97b14e568f6ec; patch: 5.15.210; cdae7c07e3e3509eaabc18c1640a55dc5b99c179 <37abc4504fa19d8f9f1e87792e8a2b8fdb308e40; cdae7c07e3e3509eaabc18c1640a55dc5b99c179 <e2d4d51cf5785815fa4e91e0c019e3eb2506a84c; 4.15; patch: 7.0.12
Die genannten Versionen sind die Angabe der Meldung. Patchlage vergleicht keine Versionsnummern und leitet aus ihnen keine Aussage ab — welche Version installiert ist, muss ein Mensch nachsehen.
Im Produktkatalog geführt
Für diese Produkte kann ein Bestand in Patchlage erfasst werden. Ein Advisory dazu erscheint am Morgen danach im Lagebericht.
- Linux — Linux
Betrifft das einen Ihrer Kundenbestände?
Diese Seite kann die Frage nicht beantworten — sie kennt Ihren Bestand nicht. Wer seine Umgebungen erfasst hat, bekommt die Antwort am Morgen nach der Veröffentlichung, zusammen mit einem Absatz, den er unverändert an den Kunden weitergeben kann.
28 Tage testenPatchlage meldet Treffer und Verdachtsfälle. Zu allem anderen sagt dieses System nichts — weder diese Seite noch der Lagebericht behauptet je, dass ein Bestand sicher ist.