Executive brief
A vulnerability was identified in the Linux kernel's AMD display driver. This component is responsible for managing how the computer communicates with AMD graphics hardware and monitors. If exploited, this flaw could lead to a system crash or potentially allow unauthorized access to system memory, impacting the stability and security of the operating system.
Technical details
Two vulnerabilities were identified in the 'dc_process_dmub_aux_transfer_async' function within the AMD display driver (drm/amd/display). First, a stack buffer overflow occurred because the function copied payload data into a fixed 16-byte buffer without runtime length validation (relying instead on a compile-time ASSERT which is removed in release builds). Second, the 'link_index' parameter was used to dereference the 'dc->links[]' array without bounds checking against 'dc->link_count', leading to a potential out-of-bounds read/write. An attacker with the ability to trigger these display-related asynchronous transfers could cause a kernel panic or achieve memory corruption. The fix introduces explicit runtime checks for both the payload length and the link index.
Affected products
- Linux Linux Kernel 5.15.209, 6.1.175, 6.6.142, 6.12.92, 6.18.34
Timeline
- 2026-05-07: other: Vulnerability fixed in source code by Harry Wentland
- 2026-06-01: patched: Patches committed to various stable kernel branches
- 2026-07-24: disclosed: CVE published to NVD
References
- https://git.kernel.org/stable/c/16a5fa57565afb6bf37e18129921c270c93d8e2b
- https://git.kernel.org/stable/c/1c8c6e912f2945b2a3e669afca6b52174b88e86e
- https://git.kernel.org/stable/c/1ecde19bfce6535bffddad1139ff466b6d401b8e
- https://git.kernel.org/stable/c/3265f3ed373fb8048be713aadcdf702579a0e53d
- https://git.kernel.org/stable/c/6c92f6d9600efa3ef0d9e560a2b52776d9803c29
- https://git.kernel.org/stable/c/90c398e822ca76e40548df0c061dd4f93ea92d71
- https://git.kernel.org/stable/c/d6590e3f766e3111dd1beaf88b9384d117acfa6b