Executive brief
A vulnerability was identified in the Linux kernel's AMD display driver that could allow an out-of-bounds memory read. This occurs when the system interacts with certain DisplayPort hardware that reports a specific number of signal repeaters. While primarily a technical stability issue, such flaws can potentially lead to system crashes or the unintended exposure of small amounts of kernel memory.
Technical details
An out-of-bounds read exists in the AMD display driver (drm/amd/display) within the Linux kernel. The 'aux_rd_interval' array in 'struct dc_lttpr_caps' was incorrectly sized at MAX_REPEATER_CNT - 1 (7 elements). When a connected DisplayPort sink reports the maximum allowed 8 LTTPR repeaters via the DisplayPort Configuration Data (DPCD), the 'dp_get_eq_aux_rd_interval()' function attempts to access the 8th index, resulting in an out-of-bounds read. This is a local vulnerability requiring the presence of specific hardware or the ability to spoof DPCD responses. The issue has been resolved by increasing the array size to MAX_REPEATER_CNT in the affected header file.
Affected products
- Linux Linux Kernel 6.18.36, 7.0.13, 7.1
Timeline
- 2026-05-05: other: Initial patch authored
- 2026-07-01: disclosed: CVE published