Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-63893— thunderbolt: property: Reject u32 wrap in tb_property_entry_valid()

CVSS 8.1 · High EPSS 0.36% · P29

Affected Version Matrix 18

VendorProductVersion RangeStatus
LinuxLinuxcdae7c07e3e3509eaabc18c1640a55dc5b99c179< 6a63623621639acbb39bc2d9fb09559681716695affected
cdae7c07e3e3509eaabc18c1640a55dc5b99c179< e8a0b0a93a6ef958e70b1dd4930beb6dc0026b36affected
cdae7c07e3e3509eaabc18c1640a55dc5b99c179< 9fee50c4e1e42f6d3cbe30df584f9f648f626071affected
cdae7c07e3e3509eaabc18c1640a55dc5b99c179< 8d4a758b407ab3de3be86d1ceadfa35d717d30c7affected
cdae7c07e3e3509eaabc18c1640a55dc5b99c179< 5c06a3043ad944f087bb2ae0aae28d820bb9f460affected
cdae7c07e3e3509eaabc18c1640a55dc5b99c179< 31b98e503ecca8077e5247253dd5425ab84bc96daffected
cdae7c07e3e3509eaabc18c1640a55dc5b99c179< a47784aee77f33f786dc5d7375db821bdae68792affected
cdae7c07e3e3509eaabc18c1640a55dc5b99c179< 01deda0152066c6c955f0619114ea6afa070aaecaffected
… +10 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-63893

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
thunderbolt: property: Reject u32 wrap in tb_property_entry_valid()
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() entry->value is u32 and entry->length is u16; the sum is performed in u32 and wraps. A malicious XDomain peer can pick value = 0xffffff00, length = 0x100 so the sum 0x100000000 wraps to 0 and passes the > block_len check. tb_property_parse() then passes entry->value to parse_dwdata() as a dword offset into the property block, reading attacker-directed memory far past the allocation. For TEXT-typed entries with the "deviceid" or "vendorid" keys this lands in xd->device_name / xd->vendor_name and is readable back via the per-XDomain device_name / vendor_name sysfs attributes; the leak is NUL-bounded (kstrdup() stops at the first zero byte) and untargeted (the attacker picks a delta, not an absolute address). DATA-typed entries are parsed into property->value.data but not generically surfaced to userspace. Use check_add_overflow() so a wrapped sum is rejected.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会开源的一款操作系统内核。 Linux kernel 4.15版本存在安全漏洞,该漏洞源于整数溢出问题,可能导致恶意XDomain对等体读取分配之外的内存。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux cdae7c07e3e3509eaabc18c1640a55dc5b99c179 ~ 6a63623621639acbb39bc2d9fb09559681716695 -
LinuxLinux 4.15 -

II. Public POCs for CVE-2026-63893

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-63893

登录查看更多情报信息。

Patches & Fixes for CVE-2026-63893 (7)

Same Patch Batch · Linux · 2026-07-19 · 431 CVEs total

CVE-2026-6379510.0 CRITICAL9p: avoid putting oldfid in p9_client_walk() error path
CVE-2026-639229.8 CRITICALipv6: exthdrs: refresh nh after handling HAO option
CVE-2026-641369.8 CRITICALsmb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked()
CVE-2026-641509.8 CRITICALnetfilter: nft_inner: release local_lock before re-enabling softirqs
CVE-2026-639249.8 CRITICALipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo()
CVE-2026-640009.8 CRITICALnet: hsr: fix potential OOB access in supervision frame handling
CVE-2026-640469.8 CRITICALnet: tls: prevent chain-after-chain in plain text SG
CVE-2026-640479.8 CRITICALnet: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring
CVE-2026-639949.8 CRITICALtunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]()
CVE-2026-641429.8 CRITICALksmbd: close durable scavenger races against m_fp_list lookups
CVE-2026-639939.8 CRITICALvxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu()
CVE-2026-533989.8 CRITICALNFSD: Fix SECINFO_NO_NAME decode error cleanup
CVE-2026-641329.8 CRITICALipv6: ioam: refresh hdr pointer before ioam6_event()
CVE-2026-533999.8 CRITICALnfsd: release layout stid on setlease failure
CVE-2026-640559.8 CRITICALnet: ethernet: cortina: Carry over frag counter
CVE-2026-641259.8 CRITICALnet: bcmgenet: keep RBUF EEE/PM disabled
CVE-2026-641229.8 CRITICALnet/mlx5e: Fix use-after-free in mlx5e_tx_reporter_timeout_recover
CVE-2026-638579.8 CRITICALnet: airoha: Do not read uninitialized fragment address in airoha_dev_xmit()
CVE-2026-639799.8 CRITICALnet/handshake: hand off the pinned file reference to accept_doit
CVE-2026-639789.8 CRITICALnet/handshake: Drain pending requests at net namespace exit

Showing top 20 of 431 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-63893

No comments yet


Leave a comment