CVE-2026-64097 (GCVE-0-2026-64097)
Vulnerability from cvelistv5
Published
2026-07-19 15:40
Modified
2026-08-05 12:39
Summary
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Validate GPIO pin LUT table size before iterating [Why&How] The GPIO pin table parsers in get_gpio_i2c_info() and bios_parser_get_gpio_pin_info() derive an element count from the VBIOS table_header.structuresize field, then iterate over gpio_pin[] entries. However, GET_IMAGE() only validates that the table header itself fits within the BIOS image. If the VBIOS reports a structuresize larger than the actual mapped data, the loop reads past the end of the BIOS image, causing an out-of-bounds read. Fix this by calling bios_get_image() to validate that the full claimed structuresize is accessible within the BIOS image before entering the loop in both functions. (cherry picked from commit ba5e95b43b773ae1bf1f66ee6b31eb774e65afe3)
Impacted products
Vendor Product Version
Linux Linux Version: ae79c310b1a6f97429a5784b65f125d9cc9c95b1
Version: ae79c310b1a6f97429a5784b65f125d9cc9c95b1
Version: ae79c310b1a6f97429a5784b65f125d9cc9c95b1
Version: ae79c310b1a6f97429a5784b65f125d9cc9c95b1
Version: ae79c310b1a6f97429a5784b65f125d9cc9c95b1
Version: ae79c310b1a6f97429a5784b65f125d9cc9c95b1
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/gpu/drm/amd/display/dc/bios/bios_parser2.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "9900f6954be779011e7c2cd42addd87baf028bc5",
              "status": "affected",
              "version": "ae79c310b1a6f97429a5784b65f125d9cc9c95b1",
              "versionType": "git"
            },
            {
              "lessThan": "fb30a3890d62fd50a95aef684faf64a307592e42",
              "status": "affected",
              "version": "ae79c310b1a6f97429a5784b65f125d9cc9c95b1",
              "versionType": "git"
            },
            {
              "lessThan": "67461e0c15335894cc5d3b84cda823bf8cbdc886",
              "status": "affected",
              "version": "ae79c310b1a6f97429a5784b65f125d9cc9c95b1",
              "versionType": "git"
            },
            {
              "lessThan": "7ca695b3122297b06a3ed605bbe1cd32c85d9f5a",
              "status": "affected",
              "version": "ae79c310b1a6f97429a5784b65f125d9cc9c95b1",
              "versionType": "git"
            },
            {
              "lessThan": "f2a4827e980ba07de4391fa84d9c39a12726bdd7",
              "status": "affected",
              "version": "ae79c310b1a6f97429a5784b65f125d9cc9c95b1",
              "versionType": "git"
            },
            {
              "lessThan": "86d2b20644b11d21fe52c596e6e922b4590a3e3f",
              "status": "affected",
              "version": "ae79c310b1a6f97429a5784b65f125d9cc9c95b1",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/gpu/drm/amd/display/dc/bios/bios_parser2.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.15"
            },
            {
              "lessThan": "4.15",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.175",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.142",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.92",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.34",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "7.0.*",
              "status": "unaffected",
              "version": "7.0.11",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.1",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.175",
                  "versionStartIncluding": "4.15",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.142",
                  "versionStartIncluding": "4.15",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.92",
                  "versionStartIncluding": "4.15",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.34",
                  "versionStartIncluding": "4.15",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.0.11",
                  "versionStartIncluding": "4.15",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.1",
                  "versionStartIncluding": "4.15",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Validate GPIO pin LUT table size before iterating\n\n[Why\u0026How]\nThe GPIO pin table parsers in get_gpio_i2c_info() and\nbios_parser_get_gpio_pin_info() derive an element count from the VBIOS\ntable_header.structuresize field, then iterate over gpio_pin[] entries.\nHowever, GET_IMAGE() only validates that the table header itself fits\nwithin the BIOS image. If the VBIOS reports a structuresize larger than\nthe actual mapped data, the loop reads past the end of the BIOS image,\ncausing an out-of-bounds read.\n\nFix this by calling bios_get_image() to validate that the full claimed\nstructuresize is accessible within the BIOS image before entering the\nloop in both functions.\n\n(cherry picked from commit ba5e95b43b773ae1bf1f66ee6b31eb774e65afe3)"
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The bug is reached only through the amdgpu DRM/display stack when the kernel parses VBIOS GPIO tables during connector/link setup (dc_create \u2192 link_create \u2192 get_gpio_i2c_info()/bios_parser_get_gpio_pin_info()); there is no network, Bluetooth, or USB packet path to this code.\nAC:L - Once a GPU carries a VBIOS with an inflated gpio_pin_lut structuresize, the derived loop count is fully attacker-controlled and the out-of-bounds read triggers deterministically on driver probe or display link initialization without races or layout-dependent conditions.\nPR:L - No capability checks guard the call path; any local user with ordinary access to the AMDGPU DRM device (typical video/render group membership) reaches the vulnerable parsers during normal display initialization, while a malicious VBIOS can be preinstalled via physical GPU reprogramming, supply-chain compromise, or prior privileged vbflash without ongoing root at trigger time.\nUI:N - Exploitation requires no victim interaction beyond system/driver startup; on laptops and servers with AMD GPUs the vulnerable parsing runs automatically during amdgpu module load and connector enumeration, including built-in eDP paths.\nS:U - Impact stays within kernel/GPU driver context on the same machine; corrupted VBIOS parsing does not cross a VM-host, container, or IOMMU security boundary even in SR-IOV or passthrough deployments.\nC:H - The loop performs an out-of-bounds read past the validated GPIO pin LUT when structuresize overstates the table, potentially reading adjacent kernel heap memory beyond the kmalloc\u0027d VBIOS image and feeding attacker-influenced bytes into subsequent GPIO register-index lookups.\nI:H - Mis-parsed out-of-bounds gpio_pin_assignment entries supply data_a_reg_index and gpio_bitshift values that drive MMIO/GPIO configuration (DDC, HPD, I2C pin setup), enabling arbitrary display-engine register targeting and memory-corruption-class integrity impact rather than a benign read-only fault.\nA:H - Invalid register offsets and masks derived from out-of-bounds data can hang or fault the display subsystem and broader kernel (GPU reset, oops, or denial of service), and uncontrolled reads past the VBIOS buffer boundary can provoke crashes under memory-hardening or on marginal hardware."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T12:39:11.518Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/9900f6954be779011e7c2cd42addd87baf028bc5"
        },
        {
          "url": "https://git.kernel.org/stable/c/fb30a3890d62fd50a95aef684faf64a307592e42"
        },
        {
          "url": "https://git.kernel.org/stable/c/67461e0c15335894cc5d3b84cda823bf8cbdc886"
        },
        {
          "url": "https://git.kernel.org/stable/c/7ca695b3122297b06a3ed605bbe1cd32c85d9f5a"
        },
        {
          "url": "https://git.kernel.org/stable/c/f2a4827e980ba07de4391fa84d9c39a12726bdd7"
        },
        {
          "url": "https://git.kernel.org/stable/c/86d2b20644b11d21fe52c596e6e922b4590a3e3f"
        }
      ],
      "title": "drm/amd/display: Validate GPIO pin LUT table size before iterating",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-64097",
    "datePublished": "2026-07-19T15:40:03.599Z",
    "dateReserved": "2026-07-19T07:54:57.033Z",
    "dateUpdated": "2026-08-05T12:39:11.518Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…