CVE-2026-68277

Source
https://cve.org/CVERecord?id=CVE-2026-68277
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68277.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-68277
Downstream
Published
2026-08-10T12:01:53Z
Modified
2026-08-25T03:30:16Z
Summary
drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers
Details

In the Linux kernel, the following vulnerability has been resolved:

drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers

Three sideband reply parsers read 16-bit fields as:

val = (raw->msg[idx] << 8) | (raw->msg[idx+1]);

and check bounds only after the fact. When idx == raw->curlen, raw->msg[idx+1] reads one byte past the received message data into the following struct fields (curchunk_len, curchunk_idx, curlen).

Affected functions:

  • drm_dp_sideband_parse_enum_path_resources_ack() full_payload_bw_number and avail_payload_bw_number fields
  • drm_dp_sideband_parse_allocate_payload_ack() allocated_pbn field
  • drm_dp_sideband_parse_query_payload_ack() allocated_pbn field

Fix by using a single combined check (idx + 2 > curlen) before each 2-byte read. Since the check is strictly tighter than idx > curlen, no separate step is needed.

[added fixes tag]

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68277.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ad7f8a1f9ced7f049f9b66d588723f243a7034cd
Fixed
c1f72a13d54ffd16647d3fa540d961f5deba8790
Fixed
192e146c2d57ad033b0d418ec64ee390f8dc074e
Fixed
6e3107e6522109a07fc9bb0fc4ec463f1982e113
Fixed
bdf0508b1e6785d4a8982c637e97e68d60b47d7b
Fixed
0bcd7675c69a2462a8531fcd9e4d096e9c7ec5df
Fixed
d5c70523cafa26ad2c7a37b612849abe2683baa8
Fixed
68a624416d1dd481b3e5b7ea0e8a070a9b8a2c73
Fixed
6b89ba3dba2f583626fb693e47e951ffb8bf591f

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68277.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.17.0
Fixed
5.10.266
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.217
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.183
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.148
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.101
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.42
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.6

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68277.json"