PT-2026-106510 · Linux · Linux
CVE-2026-98181
·
Published
2026-10-06
·
Updated
2026-10-06
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
drm/gud: fix out-of-bounds write in gud plane atomic check()
The plane property loop uses req->properties[num properties + i] as write
index while simultaneously incrementing
num properties inside the loop.
At iteration i, num properties has also incremented by i, so the write
is done at initial num properties + 2*i, skipping every other index and
advancing by 2 per iteration.With just 2 connector and 32 plane properties the last write happens at
index 64, one slot past the end of the 64-slot (indices 0–63)
allocation. A USB device can trigger OOB by advertising the maximum
number of properties.
Fix by dropping the redundant
+ i; num properties is already the correct
running index, as gud connector fill properties() fills the preceding
slots. Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux