๐Ÿ” CVE Alert

CVE-2026-93234

UNKNOWN 0.0

drm/gud: validate TV mode names before creating enum property

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: drm/gud: validate TV mode names before creating enum property The GUD protocol returns TV mode names as fixed-size GUD_CONNECTOR_TV_MODE_NAME_LEN entries and requires each name to be NUL-terminated. gud_connector_add_tv_mode() currently passes each fixed-size entry directly to drm_mode_create_tv_properties_legacy(), which eventually reaches drm_property_add_enum() and strlen(). If a device returns an entry without a terminating NUL byte, strlen() reads past the end of the slot and can run beyond the allocated buffer, triggering an out-of-bounds read. Validate that each returned TV mode name contains a NUL terminator within its fixed-size slot before passing it to the DRM property code. If a malformed entry is found, reject the device response with -EIO. This fixes the out-of-bounds read without changing the handling of valid devices, and avoids silently truncating malformed protocol data.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 24, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
40e1a70b4aedf2859a1829991b48ef0ebe650bf2 < 676f1fb3632bbc9ce83be7938e93fe6bfc9510fd 40e1a70b4aedf2859a1829991b48ef0ebe650bf2 < 06fcaf21c18ac88f57fee3803554f48c6026b95f 40e1a70b4aedf2859a1829991b48ef0ebe650bf2 < 082e378886547b5b1c4075ed307f7c68547868dc 40e1a70b4aedf2859a1829991b48ef0ebe650bf2 < 70cffc31a380b3eae45027101647aa94c242aa0e 40e1a70b4aedf2859a1829991b48ef0ebe650bf2 < 72a95df6bbc7d20c7af1e39d86b3e910cccd01ad 40e1a70b4aedf2859a1829991b48ef0ebe650bf2 < eab46d9629807db1b5647d17227e16110a18227f 40e1a70b4aedf2859a1829991b48ef0ebe650bf2 < da1ea35fea67ad841f4ada28dd61b41be65e5437
Linux / Linux
5.13

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/676f1fb3632bbc9ce83be7938e93fe6bfc9510fd git.kernel.org: https://git.kernel.org/stable/c/06fcaf21c18ac88f57fee3803554f48c6026b95f git.kernel.org: https://git.kernel.org/stable/c/082e378886547b5b1c4075ed307f7c68547868dc git.kernel.org: https://git.kernel.org/stable/c/70cffc31a380b3eae45027101647aa94c242aa0e git.kernel.org: https://git.kernel.org/stable/c/72a95df6bbc7d20c7af1e39d86b3e910cccd01ad git.kernel.org: https://git.kernel.org/stable/c/eab46d9629807db1b5647d17227e16110a18227f git.kernel.org: https://git.kernel.org/stable/c/da1ea35fea67ad841f4ada28dd61b41be65e5437