PT-2026-106510 · Linux · Linux

CVE-2026-98181

·

Published

2026-10-06

·

Updated

2026-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
drm/gud: fix out-of-bounds write in gud plane atomic check()
The plane property loop uses req->properties[num properties + i] as write index while simultaneously incrementing num properties inside the loop. At iteration i, num properties has also incremented by i, so the write is done at initial num properties + 2*i, skipping every other index and advancing by 2 per iteration.
With just 2 connector and 32 plane properties the last write happens at index 64, one slot past the end of the 64-slot (indices 0–63) allocation. A USB device can trigger OOB by advertising the maximum number of properties.
Fix by dropping the redundant + i; num properties is already the correct running index, as gud connector fill properties() fills the preceding slots.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98181

Affected Products

Linux