Back to overview

CVE-2026-64097

Description
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Validate GPIO pin LUT table size before iterating [Why&How] The GPIO pin table parsers in get_gpio_i2c_info() and bios_parser_get_gpio_pin_info() derive an element count from the VBIOS table_header.structuresize field, then iterate over gpio_pin[] entries. However, GET_IMAGE() only validates that the table header itself fits within the BIOS image. If the VBIOS reports a structuresize larger than the actual mapped data, the loop reads past the end of the BIOS image, causing an out-of-bounds read. Fix this by calling bios_get_image() to validate that the full claimed structuresize is accessible within the BIOS image before entering the loop in both functions. (cherry picked from commit ba5e95b43b773ae1bf1f66ee6b31eb774e65afe3)

Metadata

CVE ID
CVE-2026-64097
State
PUBLISHED
Assigner
Linux
Reserved
2026-07-19 07:54 UTC
Published
2026-07-19 15:40 UTC
Last updated
2026-07-20 06:41 UTC
Vendor / Product
Linux / Linux
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (2)
VendorProductPlatformVersions
Linux Linux ae79c310b1a6f97429a5784b65f125d9cc9c95b1 < 9900f6954be779011e7c2cd42addd87baf028bc5, ae79c310b1a6f97429a5784b65f125d9cc9c95b1 < fb30a3890d62fd50a95aef684faf64a307592e42, ae79c310b1a6f97429a5784b65f125d9cc9c95b1 < 67461e0c15335894cc5d3b84cda823bf8cbdc886, ae79c310b1a6f97429a5784b65f125d9cc9c95b1 < 7ca695b3122297b06a3ed605bbe1cd32c85d9f5a …
Linux Linux 4.15, 0 < 4.15, 6.1.175 ≤ 6.1.*, 6.6.142 ≤ 6.6.* …
Back to overview