A vulnerability marked as critical has been reported in Linux Kernel up to 6.12.92/6.18.34/7.0.11. This impacts the function
cmis_fw_update_start_download of the component Cmis. Performing a manipulation results in out-of-bounds write.
This vulnerability was named CVE-2026-63995. The attack needs to be approached locally. There is no available exploit.