CVE-2026-68279
CVE CVE-2026-68279EUVD EUVD-2026-55380Published 2026-08-10T12:02:09.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers drm_dp_sideband_parse_remote_dpcd_read() reads num_bytes from the raw message and then unconditionally does: memcpy(bytes, &raw->msg[idx], num_bytes); without checking that idx + num_bytes <= raw->curlen. raw->msg[] is 256 bytes; if a malicious or misbehaving MST hub sets num_bytes larger than the remaining payload, the memcpy reads past the received data into whatever follows in raw->msg[]. drm_dp_sideband_parse_remote_i2c_read_ack() has the same flaw (noted with a /* TODO check */ comment since the code was introduced). Fix both functions by using a single combined check (idx + num_bytes > curlen) before each memcpy. Since num_bytes is u8, it is always >= 0, so this strictly subsumes the simpler idx > curlen form and no separate step is needed. [added missing fixes tag]
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux ad7f8a1f9ced7f049f9b66d588723f243a7034cd <e6ef5455b06cb4e5d181aabcd723791587c79f12; patch: 7.1.6; ad7f8a1f9ced7f049f9b66d588723f243a7034cd <533d9e2bede4aeefdc2a0561d7071cfede95958f; patch: 6.18.42; patch: 7.2-rc1; 3.17; ad7f8a1f9ced7f049f9b66d588723f243a7034cd <04d953f50d61e542e94a5977822cc53735f8c0ce; ad7f8a1f9ced7f049f9b66d588723f243a7034cd <22d9f7fc1aaabaf73d5f30e8b0c9aa814ecd6ed2; ad7f8a1f9ced7f049f9b66d588723f243a7034cd <1a8f537f5a1eeac941f262fe73078d6b08ba83c0; patch: 6.12.101; patch: 0; patch: 6.6.148
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.