CVE-2026-89817

Summary

In the Linux kernel, the following vulnerability has been resolved:

drm/gud: NUL-terminate TV mode names read from the device

gud_connector_add_tv_mode() reads a buffer of fixed-size mode names from the USB device and passes pointers into it to drm_mode_create_tv_properties_legacy(), which calls strlen() on each one. Nothing guarantees the device NUL-terminates a name, so strlen() can run past the end of a slot and, for the last mode, past the end of the allocation.

Terminate each name at the end of its slot before use.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux40e1a70b4aedf2859a1829991b48ef0ebe650bf2 < 08c8ec28547987e55a90c662f8795e05c2925498affected
LinuxLinux40e1a70b4aedf2859a1829991b48ef0ebe650bf2 < 9096edfd6f2edbc79612b482547e0972edbcfe4baffected
LinuxLinux40e1a70b4aedf2859a1829991b48ef0ebe650bf2 < 89210cb5ff8fdbe055c97ac688be2268f6c815aeaffected
LinuxLinux40e1a70b4aedf2859a1829991b48ef0ebe650bf2 < d0f3312f7800eb0e00d1264f66104c788f43dd69affected
LinuxLinux40e1a70b4aedf2859a1829991b48ef0ebe650bf2 < b86438a5c6b0250ccb07dd380184d1e70e0dea6caffected
LinuxLinux40e1a70b4aedf2859a1829991b48ef0ebe650bf2 < 6ea61f1d4cbaa0db937e31bffc041fb8afeacf52affected
LinuxLinux40e1a70b4aedf2859a1829991b48ef0ebe650bf2 < 500cb24cd61bad8a2747ddfc49b7034899c82d94affected
LinuxLinux5.13affected
LinuxLinux0 < 5.13unaffected
LinuxLinux5.15.221 <= 5.15.*unaffected
LinuxLinux6.1.188 <= 6.1.*unaffected
LinuxLinux6.6.157 <= 6.6.*unaffected
LinuxLinux6.12.110 <= 6.12.*unaffected
LinuxLinux6.18.51 <= 6.18.*unaffected
LinuxLinux7.2.5 <= 7.2.*unaffected
LinuxLinux7.3-rc2 <= *unaffected

Weaknesses

References