PT-2026-54824 · Linux+2 · Linux Kernel+2

CVE-2026-53356

·

Published

2026-07-01

·

Updated

2026-09-07

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the drm/i915/gem component where the sg page() function returns a struct page pointer instead of a void pointer. This causes incorrect scaling during pread and pwrite operations for physical Buffer Objects (BO), leading to the access of incorrect BO segments when a non-zero offset is utilized. This affects platforms using physical mapping for overlay or cursor planes, such as Gen3/945G/Lakeport.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALSA-2026:57251
ALSA-2026:57252
CVE-2026-53356
ECHO-7647-9196-02B1
OPENSUSE-SU-2026:21555-1
SUSE-SU-2026:23066-1
SUSE-SU-2026:23068-1
SUSE-SU-2026:23193-1
SUSE-SU-2026:23194-1
SUSE-SU-2026:23221-1
SUSE-SU-2026:23231-1
SUSE-SU-2026:23237-1
SUSE-SU-2026:23241-1
SUSE-SU-2026:23244-1
SUSE-SU-2026:3130-1
SUSE-SU-2026:3166-1
USN-8726-1
USN-8727-1
USN-8728-1

Affected Products

Linux Kernel
Rocky Linux
Ubuntu