-

CVE-2026-98181

drm/gud: fix out-of-bounds write in gud_plane_atomic_check()

In the Linux kernel, the following vulnerability has been resolved:

drm/gud: fix out-of-bounds write in gud_plane_atomic_check()

The plane property loop uses req->properties[num_properties + i] as write
index while simultaneously incrementing `num_properties` inside the loop.
At iteration i, num_properties has also incremented by i, so the write
is done at `initial_num_properties + 2*i`, skipping every other index and
advancing by 2 per iteration.

With just 2 connector and 32 plane properties the last write happens at
index 64, one slot past the end of the 64-slot (indices 0–63)
allocation. A USB device can trigger OOB by advertising the maximum
number of properties.

Fix by dropping the redundant `+ i`; num_properties is already the correct
running index, as gud_connector_fill_properties() fills the preceding
slots.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 40e1a70b4aedf2859a1829991b48ef0ebe650bf2
Version < ee04903fe6a098160d20dde4fc5af4cb42846735
Status affected
Version 40e1a70b4aedf2859a1829991b48ef0ebe650bf2
Version < 4153a9e008f2512bd3cf90a319436865847369b9
Status affected
Version 40e1a70b4aedf2859a1829991b48ef0ebe650bf2
Version < 5f5e565410b4987e9663f599f9ab0c350f8338d4
Status affected
Version 40e1a70b4aedf2859a1829991b48ef0ebe650bf2
Version < 7e630edb22088df7aa0d55b02237a71e4c9a523d
Status affected
Version 40e1a70b4aedf2859a1829991b48ef0ebe650bf2
Version < 2c92af27ad23e2fbc0367b11a9027d36d94ef4b3
Status affected
Version 40e1a70b4aedf2859a1829991b48ef0ebe650bf2
Version < ea57100955c1c2a525ba1a98c18d9a05b25aeedb
Status affected
Version 40e1a70b4aedf2859a1829991b48ef0ebe650bf2
Version < 59ced288fcba9e91bd38e61a972ad782c4edb7d0
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.13
Status affected
Version 0
Version < 5.13
Status unaffected
Version <= 5.15.*
Version 5.15.222
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.112
Status unaffected
Version <= 6.18.*
Version 6.18.54
Status unaffected
Version <= 7.2.*
Version 7.2.8
Status unaffected
Version <= *
Version 7.3-rc4
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.06
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/ee04903fe6a098160d20dde4fc5af4cb42846735
https://git.kernel.org/stable/c/4153a9e008f2512bd3cf90a319436865847369b9
https://git.kernel.org/stable/c/5f5e565410b4987e9663f599f9ab0c350f8338d4
https://git.kernel.org/stable/c/7e630edb22088df7aa0d55b02237a71e4c9a523d
https://git.kernel.org/stable/c/2c92af27ad23e2fbc0367b11a9027d36d94ef4b3
https://git.kernel.org/stable/c/ea57100955c1c2a525ba1a98c18d9a05b25aeedb
https://git.kernel.org/stable/c/59ced288fcba9e91bd38e61a972ad782c4edb7d0