-
CVE-2026-97621
- EPSS 0.2%
- Veröffentlicht 25.09.2026 10:22:26
- Zuletzt bearbeitet 25.09.2026 11:17:16
- Erkennungen
drm/rockchip: analogix_dp: fix unchecked bound endpoint name length
In the Linux kernel, the following vulnerability has been resolved: drm/rockchip: analogix_dp: fix unchecked bound endpoint name length rockchip_dp_drm_encoder_enable() uses sprintf() to format a device tree path into a 32-byte stack buffer. Device tree paths are not limited to this size, so a sufficiently long path can overflow the buffer. Use snprintf() with the destination size to truncate the generated name and keep the writes within bounds.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
729f8eefdcadaff98606931e691910f17d8d59d6
Version <
49f5268f43a791dd0d9ff554cce25a3685c7250b
Status
affected
Version
729f8eefdcadaff98606931e691910f17d8d59d6
Version <
2fcd112caa4ebc64fdcb509f0b26d8daa3fac950
Status
affected
Version
729f8eefdcadaff98606931e691910f17d8d59d6
Version <
bc69439d983cc491cc86e01fafc1deb94e1bb85e
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
6.16
Status
affected
Version
0
Version <
6.16
Status
unaffected
Version <=
6.18.*
Version
6.18.53
Status
unaffected
Version <=
7.2.*
Version
7.2.7
Status
unaffected
Version <=
*
Version
7.3-rc3
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.2% | 0.086 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/49f5268f43a791dd0d9ff554cce25a3685c7250b
https://git.kernel.org/stable/c/2fcd112caa4ebc64fdcb509f0b26d8daa3fac950
https://git.kernel.org/stable/c/bc69439d983cc491cc86e01fafc1deb94e1bb85e