CVE-2026-68235

Source
https://cve.org/CVERecord?id=CVE-2026-68235
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68235.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-68235
Downstream
Published
2026-08-10T12:01:00Z
Modified
2026-08-20T03:36:27Z
Summary
drm/amd/display: dce100: skip non-DP stream encoders for DP MST
Details

In the Linux kernel, the following vulnerability has been resolved:

drm/amd/display: dce100: skip non-DP stream encoders for DP MST

On DCE8-class ASICs (e.g. Bonaire), the resource pool contains digital DIG stream encoders plus one analog DAC encoder. When assigning a stream encoder for a second DisplayPort MST stream, if the preferred digital encoder is already acquired, dce100_find_first_free_match_stream_enc_for_link() falls back to the first free pool entry. That entry may be the analog encoder, whose funcs table lacks DP hooks such as dp_set_stream_attribute. The subsequent atomic commit then dereferences NULL function pointers in link_set_dpms_on() and crashes.

Skip encoders without dp_set_stream_attribute when the stream uses a DP signal (including MST). Use dc_is_dp_signal(stream->signal) for the MST fallback path instead of checking only the link connector signal.

Tested on:

  • GPU: AMD Radeon R7 260X (Bonaire / DCE8)
  • Board: Supermicro C9X299-PG300
  • Setup: DP MST daisy chain, hotplug second monitor or have it connected on boot
  • Kernel: 7.1.3 (issue observed since 6.19)
  • Result: kernel oops without patch; dual monitors stable with patch

(cherry picked from commit 28ec64943e3ee4d9b8d30cea61e380f1429953a8)

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68235.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
5834c33fd3f6f2a26dd4d6d4bbc7b8ed1c2ac4aa
Fixed
ed2d86aef9fa4c43f82da0fca91a60f7326d7d03
Fixed
d340cba0df4cf327c7e89c7c1a4e79d4771d7dd5

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68235.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.6

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68235.json"