-

CVE-2026-68278

drm/dp/mst: fix buffer overflows in sideband chunk accumulation

In the Linux kernel, the following vulnerability has been resolved:

drm/dp/mst: fix buffer overflows in sideband chunk accumulation

drm_dp_sideband_append_payload() has three related bugs when processing
device-provided sideband reply data:

1. Zero-length curchunk_len underflow: msg_len is a 6-bit field taken
   directly from the DP sideband header. If a device sends msg_len=0,
   curchunk_len is set to zero. The condition (curchunk_idx >= curchunk_len)
   is immediately true, and curchunk_len-1 wraps to 255 (u8 underflow).
   drm_dp_msg_data_crc4() reads 255 bytes from chunk[48], then memcpy()
   writes 255 bytes into msg[], both far out of bounds.

2. chunk[48] overflow: curchunk_len can reach 63 (6-bit field). chunk[] is
   only 48 bytes. Multi-iteration payload assembly appends 16-byte blocks
   until curchunk_idx reaches curchunk_len, writing up to 15 bytes past
   the end of chunk[] into msg[].

3. msg[256] overflow: each chunk contributes (curchunk_len-1) bytes to
   msg[]. No check ensures curlen + (curchunk_len-1) stays within msg[256],
   so the memcpy can spill into adjacent struct fields.

All three are reachable from any DP MST device that can forge sideband
reply messages on a physical connection.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version ad7f8a1f9ced7f049f9b66d588723f243a7034cd
Version < ef2ecb6cf268debf3890df99fea01b6452dcf78e
Status affected
Version ad7f8a1f9ced7f049f9b66d588723f243a7034cd
Version < d4e05dedb252ed3e540a0c9be511e427f098110a
Status affected
Version ad7f8a1f9ced7f049f9b66d588723f243a7034cd
Version < 4d5109075a787de28c9e89940f9dee45269f91fa
Status affected
Version ad7f8a1f9ced7f049f9b66d588723f243a7034cd
Version < 53937a2787d29c7a460e984dc4f20ff6ac91dc65
Status affected
Version ad7f8a1f9ced7f049f9b66d588723f243a7034cd
Version < ef0dbcc200c3389f1f781ab181932a97e54b51af
Status affected
Version ad7f8a1f9ced7f049f9b66d588723f243a7034cd
Version < 1e5827839ad0ceb0079d1560c321fa3656b54f21
Status affected
Version ad7f8a1f9ced7f049f9b66d588723f243a7034cd
Version < a6366b551079c79bf7bdbadd74c97358bcfe2d58
Status affected
Version ad7f8a1f9ced7f049f9b66d588723f243a7034cd
Version < 55bd5e685bda455b9b50c835f8c8442d52a344a3
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 3.17
Status affected
Version 0
Version < 3.17
Status unaffected
Version <= 5.10.*
Version 5.10.266
Status unaffected
Version <= 5.15.*
Version 5.15.217
Status unaffected
Version <= 6.1.*
Version 6.1.183
Status unaffected
Version <= 6.6.*
Version 6.6.148
Status unaffected
Version <= 6.12.*
Version 6.12.101
Status unaffected
Version <= 6.18.*
Version 6.18.42
Status unaffected
Version <= 7.1.*
Version 7.1.6
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.23% 0.143
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/53937a2787d29c7a460e984dc4f20ff6ac91dc65
https://git.kernel.org/stable/c/ef0dbcc200c3389f1f781ab181932a97e54b51af
https://git.kernel.org/stable/c/1e5827839ad0ceb0079d1560c321fa3656b54f21
https://git.kernel.org/stable/c/a6366b551079c79bf7bdbadd74c97358bcfe2d58
https://git.kernel.org/stable/c/55bd5e685bda455b9b50c835f8c8442d52a344a3
https://git.kernel.org/stable/c/4d5109075a787de28c9e89940f9dee45269f91fa
https://git.kernel.org/stable/c/d4e05dedb252ed3e540a0c9be511e427f098110a
https://git.kernel.org/stable/c/ef2ecb6cf268debf3890df99fea01b6452dcf78e