Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-63905

Published Jul 19, 2026 EPSS 0.22% (12th pctl)

Overview

CVE-2026-63905 is a known-severity vulnerability. It was published on July 19, 2026.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

usbip: vudc: Fix use after free bug in vudc_remove due to race condition

This patch follows up Zheng Wang's 2023 report of a use-after-free in

vudc_remove(). The original thread stalled on Shuah Khan's request for

runtime testing of the unplug/unbind path. This patch supplies that

testing and keeps Zheng's original fix shape.

In vudc_probe(), v_init_timer() binds udc->tr_timer.timer to v_timer().

usbip_sockfd_store() starts the timer via v_start_timer()/v_kick_timer().

vudc_remove() can then free the containing struct vudc while the timer is

still pending or executing.

KASAN confirms the race on an unpatched x86_64 QEMU guest with

CONFIG_KASAN=y, CONFIG_USBIP_VUDC=y, CONFIG_USB_ZERO=y, and a tight loop

that repeatedly writes a socket fd to usbip_sockfd, closes the socket

pair, and unbinds/rebinds usbip-vudc.0:

BUG: KASAN: slab-use-after-free in __run_timer_base.part.0+0x8ba/0x8e0

Write of size 8 at addr ffff88

Remediation

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Frequently Asked Questions

What is CVE-2026-63905?

CVE-2026-63905 is a known-severity vulnerability. It was published on July 19, 2026.

How severe is CVE-2026-63905?

CVSS score information is not yet available for this vulnerability. Check back as the CVE record is updated by NVD analysts.

How do I fix or remediate CVE-2026-63905?

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-63905?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-63905 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.