PT-2026-61208 · Linux+1 · Linux Kernel+1
CVE-2026-63891
·
Published
2026-07-19
·
Updated
2026-09-07
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the thunderbolt component where the
tb property parse dir() function lacks a recursion depth counter when processing DIRECTORY entries. A malicious XDomain peer can create a back-reference loop using crafted DIRECTORY entries, causing the parser to exhaust the kernel stack and trigger a guard page. This can be executed without authentication by any untrusted XDomain peer that can reach the PROPERTIES REQUEST control-plane exchange.Recommendations
Update the Linux kernel to a version where a depth counter is implemented in
tb property parse() and tb property parse dir() to reject blocks exceeding the maximum depth.
Disable XDomain host-to-host discovery by adding thunderbolt.xdomain=0 to the kernel command line.Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel
Ubuntu