A vulnerability categorized as very critical has been discovered in Linux Kernel. Impacted is the function
cmis_cdb_process_reply of the component Cmis. Such manipulation of the argument rpl_len/rpl_exp_len leads to out-of-bounds write.
This vulnerability is listed as CVE-2026-63996. The attack must be carried out locally. There is no available exploit.