GHSA-MRF5-P4FW-FR76

Vulnerability from github – Published: 2026-10-06 09:31 – Updated: 2026-10-06 09:31
VLAI
Details

In the Linux kernel, the following vulnerability has been resolved:

drm/gud: fix out-of-bounds write in gud_plane_atomic_check()

The plane property loop uses req->properties[num_properties + i] as write index while simultaneously incrementing num_properties inside the loop. At iteration i, num_properties has also incremented by i, so the write is done at initial_num_properties + 2*i, skipping every other index and advancing by 2 per iteration.

With just 2 connector and 32 plane properties the last write happens at index 64, one slot past the end of the 64-slot (indices 0–63) allocation. A USB device can trigger OOB by advertising the maximum number of properties.

Fix by dropping the redundant + i; num_properties is already the correct running index, as gud_connector_fill_properties() fills the preceding slots.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2026-98181"
  ],
  "database_specific": {
    "cwe_ids": [],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-10-06T09:18:02Z",
    "severity": null
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/gud: fix out-of-bounds write in gud_plane_atomic_check()\n\nThe plane property loop uses req-\u003eproperties[num_properties + i] as write\nindex while simultaneously incrementing `num_properties` inside the loop.\nAt iteration i, num_properties has also incremented by i, so the write\nis done at `initial_num_properties + 2*i`, skipping every other index and\nadvancing by 2 per iteration.\n\nWith just 2 connector and 32 plane properties the last write happens at\nindex 64, one slot past the end of the 64-slot (indices 0\u201363)\nallocation. A USB device can trigger OOB by advertising the maximum\nnumber of properties.\n\nFix by dropping the redundant `+ i`; num_properties is already the correct\nrunning index, as gud_connector_fill_properties() fills the preceding\nslots.",
  "id": "GHSA-mrf5-p4fw-fr76",
  "modified": "2026-10-06T09:31:29Z",
  "published": "2026-10-06T09:31:29Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-98181"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/2c92af27ad23e2fbc0367b11a9027d36d94ef4b3"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/4153a9e008f2512bd3cf90a319436865847369b9"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/59ced288fcba9e91bd38e61a972ad782c4edb7d0"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/5f5e565410b4987e9663f599f9ab0c350f8338d4"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/7e630edb22088df7aa0d55b02237a71e4c9a523d"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/ea57100955c1c2a525ba1a98c18d9a05b25aeedb"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/ee04903fe6a098160d20dde4fc5af4cb42846735"
    }
  ],
  "schema_version": "1.4.0",
  "severity": []
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…