Описание
In the Linux kernel, the following vulnerability has been resolved:
drm/gud: NUL-terminate TV mode names read from the device
gud_connector_add_tv_mode() reads a buffer of fixed-size mode names from the USB device and passes pointers into it to drm_mode_create_tv_properties_legacy(), which calls strlen() on each one. Nothing guarantees the device NUL-terminates a name, so strlen() can run past the end of a slot and, for the last mode, past the end of the allocation.
Terminate each name at the end of its slot before use.
In the Linux kernel, the following vulnerability has been resolved:
drm/gud: NUL-terminate TV mode names read from the device
gud_connector_add_tv_mode() reads a buffer of fixed-size mode names from the USB device and passes pointers into it to drm_mode_create_tv_properties_legacy(), which calls strlen() on each one. Nothing guarantees the device NUL-terminates a name, so strlen() can run past the end of a slot and, for the last mode, past the end of the allocation.
Terminate each name at the end of its slot before use.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2026-89817
- https://git.kernel.org/stable/c/08c8ec28547987e55a90c662f8795e05c2925498
- https://git.kernel.org/stable/c/500cb24cd61bad8a2747ddfc49b7034899c82d94
- https://git.kernel.org/stable/c/6ea61f1d4cbaa0db937e31bffc041fb8afeacf52
- https://git.kernel.org/stable/c/89210cb5ff8fdbe055c97ac688be2268f6c815ae
- https://git.kernel.org/stable/c/9096edfd6f2edbc79612b482547e0972edbcfe4b
- https://git.kernel.org/stable/c/b86438a5c6b0250ccb07dd380184d1e70e0dea6c
- https://git.kernel.org/stable/c/d0f3312f7800eb0e00d1264f66104c788f43dd69
EPSS
CVE ID
Связанные уязвимости
(In the Linux kernel, the following vulnerability has been resolved: d ...)
In the Linux kernel, the following vulnerability has been resolved: drm/gud: NUL-terminate TV mode names read from the device gud_connector_add_tv_mode() reads a buffer of fixed-size mode names from the USB device and passes pointers into it to drm_mode_create_tv_properties_legacy(), which calls strlen() on each one. Nothing guarantees the device NUL-terminates a name, so strlen() can run past the end of a slot and, for the last mode, past the end of the allocation. Terminate each name at the end of its slot before use.
In the Linux kernel, the following vulnerability has been resolved: d ...
EPSS