Executive brief
A vulnerability was identified in the Linux kernel's graphics subsystem (DRM) that could allow a local user to cause a system crash or potentially access restricted memory. The issue stems from how the system calculates the size of video memory buffers, which can lead to the system incorrectly approving a buffer that is too small for the requested video format. This could result in the graphics processor reading or writing data outside of the intended memory area, impacting system stability.
Technical details
A vulnerability in `drm_gem_fb_init_with_funcs()` in the Linux kernel's DRM subsystem arises from inconsistent plane dimension calculations compared to `framebuffer_check()`. While the latter uses `DIV_ROUND_UP()`, the former used plain integer division. For specific pixel formats like NV12 with odd dimensions (e.g., 1-pixel height), this causes a sub-sampled plane height to be calculated as 0 instead of 1. Subsequent size validation logic involving `(height - 1)` results in an unsigned integer underflow to `UINT_MAX`, causing the `min_size` check to wrap and pass for undersized GEM objects. This allows the GPU to perform out-of-bounds reads or writes on the chroma plane. The issue is fixed by using `drm_format_info_plane_width/height()` to ensure consistent rounding.
Affected products
- Linux Linux Kernel v4.14+
Timeline
- 2026-04-20: other: Patch submitted by researcher
- 2026-05-17: patched: Commits merged into stable branches
- 2026-05-28: disclosed: CVE published
References
- https://git.kernel.org/stable/c/1a17ea9861e89585361caa8bc231bd22dc6dbe7d
- https://git.kernel.org/stable/c/1da4ab7189f1064b3b712b388772c008b4d82580
- https://git.kernel.org/stable/c/3d4c2268bd7243c3780fe32bf24ff876da272acf
- https://git.kernel.org/stable/c/6b992591e04f2cce813bcf239b354f375bbf84d3
- https://git.kernel.org/stable/c/c5fc49d8470c5ebf3b41607600f277158f159950