-

CVE-2026-93234

drm/gud: validate TV mode names before creating enum property

In the Linux kernel, the following vulnerability has been resolved:

drm/gud: validate TV mode names before creating enum property

The GUD protocol returns TV mode names as fixed-size
GUD_CONNECTOR_TV_MODE_NAME_LEN entries and requires each name to be
NUL-terminated.

gud_connector_add_tv_mode() currently passes each fixed-size entry
directly to drm_mode_create_tv_properties_legacy(), which eventually
reaches drm_property_add_enum() and strlen(). If a device returns an
entry without a terminating NUL byte, strlen() reads past the end of
the slot and can run beyond the allocated buffer, triggering an
out-of-bounds read.

Validate that each returned TV mode name contains a NUL terminator
within its fixed-size slot before passing it to the DRM property code.
If a malformed entry is found, reject the device response with -EIO.

This fixes the out-of-bounds read without changing the handling of
valid devices, and avoids silently truncating malformed protocol data.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 40e1a70b4aedf2859a1829991b48ef0ebe650bf2
Version < 676f1fb3632bbc9ce83be7938e93fe6bfc9510fd
Status affected
Version 40e1a70b4aedf2859a1829991b48ef0ebe650bf2
Version < 06fcaf21c18ac88f57fee3803554f48c6026b95f
Status affected
Version 40e1a70b4aedf2859a1829991b48ef0ebe650bf2
Version < 082e378886547b5b1c4075ed307f7c68547868dc
Status affected
Version 40e1a70b4aedf2859a1829991b48ef0ebe650bf2
Version < 70cffc31a380b3eae45027101647aa94c242aa0e
Status affected
Version 40e1a70b4aedf2859a1829991b48ef0ebe650bf2
Version < 72a95df6bbc7d20c7af1e39d86b3e910cccd01ad
Status affected
Version 40e1a70b4aedf2859a1829991b48ef0ebe650bf2
Version < eab46d9629807db1b5647d17227e16110a18227f
Status affected
Version 40e1a70b4aedf2859a1829991b48ef0ebe650bf2
Version < da1ea35fea67ad841f4ada28dd61b41be65e5437
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.13
Status affected
Version 0
Version < 5.13
Status unaffected
Version <= 5.15.*
Version 5.15.221
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.51
Status unaffected
Version <= 7.2.*
Version 7.2.5
Status unaffected
Version <= *
Version 7.3-rc2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.094
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/676f1fb3632bbc9ce83be7938e93fe6bfc9510fd
https://git.kernel.org/stable/c/06fcaf21c18ac88f57fee3803554f48c6026b95f
https://git.kernel.org/stable/c/082e378886547b5b1c4075ed307f7c68547868dc
https://git.kernel.org/stable/c/70cffc31a380b3eae45027101647aa94c242aa0e
https://git.kernel.org/stable/c/72a95df6bbc7d20c7af1e39d86b3e910cccd01ad
https://git.kernel.org/stable/c/eab46d9629807db1b5647d17227e16110a18227f
https://git.kernel.org/stable/c/da1ea35fea67ad841f4ada28dd61b41be65e5437