7.7
CVE-2026-68255
- EPSS 0.19%
- Veröffentlicht 10.08.2026 12:01:24
- Zuletzt bearbeitet 23.08.2026 13:16:35
- Erkennungen
drm/virtio: bound EDID block reads to the response buffer
In the Linux kernel, the following vulnerability has been resolved: drm/virtio: bound EDID block reads to the response buffer virtio_get_edid_block() validates the read offset only against the device-supplied resp->size field, never against the fixed-size resp->edid array. The EDID block index is driven by the device-supplied extension count, so a malicious virtio-gpu backend can advertise a large size together with a high block count and read far past the array into adjacent kernel memory, which is then surfaced in the parsed EDID (an out-of-bounds read / info leak). Also reject any read whose end exceeds the size of the edid array. Conforming EDID responses stay within the array and are unaffected.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
b4b01b4995fb15b55a2d067eb405917f5ab32709
Version <
65ce911f341ad8ff0c08922eff5bb6db75666eb0
Status
affected
Version
b4b01b4995fb15b55a2d067eb405917f5ab32709
Version <
64bedd2758eccbc74d39f7006a7ec16fa39dc901
Status
affected
Version
b4b01b4995fb15b55a2d067eb405917f5ab32709
Version <
3f506a85a905b080cadc029a1651a310479090a6
Status
affected
Version
b4b01b4995fb15b55a2d067eb405917f5ab32709
Version <
9fc2a017c5d597937e0c28b9a9669844aa796c42
Status
affected
Version
b4b01b4995fb15b55a2d067eb405917f5ab32709
Version <
2757e6e803092cf0aeaf4b735e16b5d3bdc705c5
Status
affected
Version
b4b01b4995fb15b55a2d067eb405917f5ab32709
Version <
35be0e2c6862abcd5e5f5445261f1fd910d4a9b4
Status
affected
Version
b4b01b4995fb15b55a2d067eb405917f5ab32709
Version <
375c1934ef0196d3b6d3a1eae3232bef8dae7bf7
Status
affected
Version
b4b01b4995fb15b55a2d067eb405917f5ab32709
Version <
4e1a53892ba7f8a3e1da6bfc53c83ae7c812dccd
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
5.0
Status
affected
Version
0
Version <
5.0
Status
unaffected
Version <=
5.10.*
Version
5.10.266
Status
unaffected
Version <=
5.15.*
Version
5.15.217
Status
unaffected
Version <=
6.1.*
Version
6.1.183
Status
unaffected
Version <=
6.6.*
Version
6.6.148
Status
unaffected
Version <=
6.12.*
Version
6.12.101
Status
unaffected
Version <=
6.18.*
Version
6.18.42
Status
unaffected
Version <=
7.1.*
Version
7.1.6
Status
unaffected
Version <=
*
Version
7.2
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.19% | 0.09 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 7.7 | 2.5 | 5.2 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
|
https://git.kernel.org/stable/c/9fc2a017c5d597937e0c28b9a9669844aa796c42
https://git.kernel.org/stable/c/2757e6e803092cf0aeaf4b735e16b5d3bdc705c5
https://git.kernel.org/stable/c/35be0e2c6862abcd5e5f5445261f1fd910d4a9b4
https://git.kernel.org/stable/c/375c1934ef0196d3b6d3a1eae3232bef8dae7bf7
https://git.kernel.org/stable/c/4e1a53892ba7f8a3e1da6bfc53c83ae7c812dccd
https://git.kernel.org/stable/c/3f506a85a905b080cadc029a1651a310479090a6
https://git.kernel.org/stable/c/64bedd2758eccbc74d39f7006a7ec16fa39dc901
https://git.kernel.org/stable/c/65ce911f341ad8ff0c08922eff5bb6db75666eb0