PT-2026-61208 · Linux+1 · Linux Kernel+1

CVE-2026-63891

·

Published

2026-07-19

·

Updated

2026-09-07

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the thunderbolt component where the tb property parse dir() function lacks a recursion depth counter when processing DIRECTORY entries. A malicious XDomain peer can create a back-reference loop using crafted DIRECTORY entries, causing the parser to exhaust the kernel stack and trigger a guard page. This can be executed without authentication by any untrusted XDomain peer that can reach the PROPERTIES REQUEST control-plane exchange.
Recommendations Update the Linux kernel to a version where a depth counter is implemented in tb property parse() and tb property parse dir() to reject blocks exceeding the maximum depth. Disable XDomain host-to-host discovery by adding thunderbolt.xdomain=0 to the kernel command line.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-63891
USN-8593-1
USN-8603-1
USN-8618-1
USN-8663-1
USN-8664-1
USN-8728-1

Affected Products

Linux Kernel
Ubuntu