Back to overview

CVE-2026-64097

HIGH
7.8
CVSS 3.1
Description
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Validate GPIO pin LUT table size before iterating [Why&How] The GPIO pin table parsers in get_gpio_i2c_info() and bios_parser_get_gpio_pin_info() derive an element count from the VBIOS table_header.structuresize field, then iterate over gpio_pin[] entries. However, GET_IMAGE() only validates that the table header itself fits within the BIOS image. If the VBIOS reports a structuresize larger than the actual mapped data, the loop reads past the end of the BIOS image, causing an out-of-bounds read. Fix this by calling bios_get_image() to validate that the full claimed structuresize is accessible within the BIOS image before entering the loop in both functions. (cherry picked from commit ba5e95b43b773ae1bf1f66ee6b31eb774e65afe3)

Metadata

CVE ID
CVE-2026-64097
State
PUBLISHED
Assigner
Linux
Reserved
2026-07-19 07:54 UTC
Published
2026-07-19 15:40 UTC
Last updated
2026-07-20 13:43 UTC
Vendor / Product
Linux / Linux
Sources
cve.org  ·  NVD

Severity & Metrics

7.8 HIGH CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products (2)
VendorProductPlatformVersions
Linux Linux — ae79c310b1a6f97429a5784b65f125d9cc9c95b1 < 9900f6954be779011e7c2cd42addd87baf028bc5, ae79c310b1a6f97429a5784b65f125d9cc9c95b1 < fb30a3890d62fd50a95aef684faf64a307592e42, ae79c310b1a6f97429a5784b65f125d9cc9c95b1 < 67461e0c15335894cc5d3b84cda823bf8cbdc886, ae79c310b1a6f97429a5784b65f125d9cc9c95b1 < 7ca695b3122297b06a3ed605bbe1cd32c85d9f5a …
Linux Linux — 4.15, 0 < 4.15, 6.1.175 ≤ 6.1.*, 6.6.142 ≤ 6.6.* …
CVSS scores (1)
ScoreSeverityVersionSourceVector
7.8 HIGH 3.1 cna CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Back to overview