PT-2026-52232 · Linux+2 · Linux Kernel+2

CVE-2026-53136

·

Published

2026-06-25

·

Updated

2026-09-07

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An out-of-bounds heap write can occur during driver probe due to missing validation of the HdmiRegNum and Hdmi6GRegNum fields within the VBIOS integrated info tables (v1 11 and v2 1). These fields are used as loop bounds when copying retimer I2C register settings into the fixed-size arrays dp* ext hdmi reg settings[9] and dp* ext hdmi 6g reg settings[3]. A malformed VBIOS can specify values up to 255, exceeding the array capacities. This issue is handled in the get integrated info v11() and get integrated info v2 1() functions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:55764
ALSA-2026:55765
ALSA-2026:57251
ALSA-2026:57252
AZL-90536
CVE-2026-53136
ECHO-10CF-131B-CB3F
OESA-2026-3204
OPENSUSE-SU-2026:21555-1
SUSE-SU-2026:23066-1
SUSE-SU-2026:23068-1
SUSE-SU-2026:23193-1
SUSE-SU-2026:23194-1
SUSE-SU-2026:23221-1
SUSE-SU-2026:23231-1
SUSE-SU-2026:23237-1
SUSE-SU-2026:23241-1
SUSE-SU-2026:23244-1
SUSE-SU-2026:3130-1
SUSE-SU-2026:3166-1
USN-8726-1
USN-8727-1
USN-8728-1

Affected Products

Linux Kernel
Rocky Linux
Ubuntu