Executive brief
The Linux kernel's display driver (DRM) logging component contains a bug in how it processes messages when rendering them to the console. When a message has a length of zero, the code attempts to access memory outside valid bounds, potentially exposing sensitive kernel data or causing a system crash.
Technical details
The vulnerability is an out-of-bounds read in the `drm_log_draw_kmsg_record()` function in `drivers/gpu/drm/clients/drm_log.c`. The function attempts to access `s[len - 1]` to remove a trailing newline, but `len` is an unsigned integer. When `len` is 0, the subtraction wraps around to UINT_MAX (4294967295), causing an out-of-bounds read of kernel memory. The fix adds an early return condition that checks if `len` is 0 before attempting the array access. This is a local attack that requires the ability to trigger DRM logging with an empty message, but the impact is memory disclosure or kernel crash.
Affected products
- Linux Linux kernel Multiple versions through 2026
Timeline
- 2026-09-03: disclosed
- 2026-08-23: patched