Executive brief
A vulnerability was identified in the Linux kernel's display driver for Qualcomm (MSM) hardware. When the system attempts to capture a 'snapshot' of the display state for debugging or error reporting, it may try to read memory outside of the intended range. This could lead to system instability or crashes during diagnostic procedures.
Technical details
A vulnerability in the drm/msm/dsi driver occurs because the IO address space is internally adjusted by an io_offset on DSI 6G platforms, but the corresponding size (ctrl_size) used for memory dumping is not adjusted. This leads to an out-of-bounds access when msm_disp_snapshot_add_block is called, as it attempts to read past the mapped region. The fix involves decrementing ctrl_size by the io_offset value during host initialization. This issue primarily affects diagnostic and snapshot capture paths (msm_dsi_host_snapshot).
Affected products
- Linux Linux 5.14 to 6.18.34
Timeline
- 2026-04-28: other: Patch authored
- 2026-07-24: disclosed: CVE published
References
- https://git.kernel.org/stable/c/567b5e976e2e15280d78c9ef2add1954a0bbb5b1
- https://git.kernel.org/stable/c/5b49a46baa853b26dbefa65c6c75dd9ff69f63d4
- https://git.kernel.org/stable/c/5e2c196c3430fb94225c4102b1028d0146544761
- https://git.kernel.org/stable/c/9f8274749d9010a1a72f97e547b7eb9ebb82345b
- https://git.kernel.org/stable/c/a184aec790135938b0fadb415e55accd1f8685a0
- https://git.kernel.org/stable/c/ab871d5882953e5574ae2bc47bec88c2e3d22663