CVE-2026-31729Disclosure(linux / linux_kernel)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch linux linux_kernel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: validate connector number in ucsi_notify_common() The connector number extracted from CCI via UCSI_CCI_CONNECTOR() is a 7-bit field (0-127) that is used to index into the connector array in ucsi_connector_change(). However, the array is only allocated for the number of connectors reported by the device (typically 2-4 entries). A malicious or malfunctioning device could report an out-of-range connector number in the CCI, causing an out-of-bounds array access in ucsi_connector_change(). Add a bounds check in ucsi_notify_common(), the central point where CCI is parsed after arriving from hardware, so that bogus connector numbers are rejected before they propagate further.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-129

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-11: 1Patch / Workaround · 2026-05-11: 1Technical Details · 2026-05-11: 105-11
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
Full discourse1 post
  • WindowsForum@windowsforum
    Disclosure

    🪟 CVE-2026-31729 USB-C “bogus connector number” → out-of-bounds before patched kernels save you. Translation: Windows can’t ignore Linux-on-WSL/containers anymore—kernel bugs travel. #Windows #Security https://windowsforum.com/threads/cve-2026-31729-usb-c-kernel-flaw-why-windows-teams-must-track-linux-kernels.417471/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #LinuxKernelSecurity #WslAndContainers #Cve202631729 https://t.co/nCzk7l0iwA

    Post summary

    The post announces a new CVE-2026-31729 involving a USB‑C out‑of‑bounds bug, referencing that patched kernels mitigate the issue, but it does not provide PoC, exploit, or active usage details.

    0000050
    1.1K followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--

Explore more