-

CVE-2026-68279

drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers

In the Linux kernel, the following vulnerability has been resolved:

drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers

drm_dp_sideband_parse_remote_dpcd_read() reads num_bytes from the raw
message and then unconditionally does:

  memcpy(bytes, &raw->msg[idx], num_bytes);

without checking that idx + num_bytes <= raw->curlen. raw->msg[] is
256 bytes; if a malicious or misbehaving MST hub sets num_bytes larger
than the remaining payload, the memcpy reads past the received data
into whatever follows in raw->msg[].

drm_dp_sideband_parse_remote_i2c_read_ack() has the same flaw (noted
with a /* TODO check */ comment since the code was introduced).

Fix both functions by using a single combined check
(idx + num_bytes > curlen) before each memcpy. Since num_bytes is u8,
it is always >= 0, so this strictly subsumes the simpler idx > curlen
form and no separate step is needed.

[added missing fixes tag]
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version ad7f8a1f9ced7f049f9b66d588723f243a7034cd
Version < 185de1d74e658e2edb723ba76fa61903f77d8a68
Status affected
Version ad7f8a1f9ced7f049f9b66d588723f243a7034cd
Version < d7b9b1e33b4ed8c48d4db6e6e21c257ebbbb2586
Status affected
Version ad7f8a1f9ced7f049f9b66d588723f243a7034cd
Version < c2fbda0fe0163c55ba3820ee6cea0c6b43622eda
Status affected
Version ad7f8a1f9ced7f049f9b66d588723f243a7034cd
Version < 22d9f7fc1aaabaf73d5f30e8b0c9aa814ecd6ed2
Status affected
Version ad7f8a1f9ced7f049f9b66d588723f243a7034cd
Version < 04d953f50d61e542e94a5977822cc53735f8c0ce
Status affected
Version ad7f8a1f9ced7f049f9b66d588723f243a7034cd
Version < 533d9e2bede4aeefdc2a0561d7071cfede95958f
Status affected
Version ad7f8a1f9ced7f049f9b66d588723f243a7034cd
Version < e6ef5455b06cb4e5d181aabcd723791587c79f12
Status affected
Version ad7f8a1f9ced7f049f9b66d588723f243a7034cd
Version < 1a8f537f5a1eeac941f262fe73078d6b08ba83c0
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 3.17
Status affected
Version 0
Version < 3.17
Status unaffected
Version <= 5.10.*
Version 5.10.266
Status unaffected
Version <= 5.15.*
Version 5.15.217
Status unaffected
Version <= 6.1.*
Version 6.1.183
Status unaffected
Version <= 6.6.*
Version 6.6.148
Status unaffected
Version <= 6.12.*
Version 6.12.101
Status unaffected
Version <= 6.18.*
Version 6.18.42
Status unaffected
Version <= 7.1.*
Version 7.1.6
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.079
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/22d9f7fc1aaabaf73d5f30e8b0c9aa814ecd6ed2
https://git.kernel.org/stable/c/04d953f50d61e542e94a5977822cc53735f8c0ce
https://git.kernel.org/stable/c/533d9e2bede4aeefdc2a0561d7071cfede95958f
https://git.kernel.org/stable/c/e6ef5455b06cb4e5d181aabcd723791587c79f12
https://git.kernel.org/stable/c/1a8f537f5a1eeac941f262fe73078d6b08ba83c0
https://git.kernel.org/stable/c/c2fbda0fe0163c55ba3820ee6cea0c6b43622eda
https://git.kernel.org/stable/c/185de1d74e658e2edb723ba76fa61903f77d8a68
https://git.kernel.org/stable/c/d7b9b1e33b4ed8c48d4db6e6e21c257ebbbb2586