PT-2026-52232 · Linux+2 · Linux Kernel+2
CVE-2026-53136
·
Published
2026-06-25
·
Updated
2026-09-07
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An out-of-bounds heap write can occur during driver probe due to missing validation of the
HdmiRegNum and Hdmi6GRegNum fields within the VBIOS integrated info tables (v1 11 and v2 1). These fields are used as loop bounds when copying retimer I2C register settings into the fixed-size arrays dp* ext hdmi reg settings[9] and dp* ext hdmi 6g reg settings[3]. A malformed VBIOS can specify values up to 255, exceeding the array capacities. This issue is handled in the get integrated info v11() and get integrated info v2 1() functions.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linux Kernel
Rocky Linux
Ubuntu