Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-94842.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-94842
Upstream
Published
2026-08-10T13:20:13Z
Modified
2026-08-30T05:26:50Z
Summary
CVE-2026-68253 affecting package kernel 6.6.150.1-1
Details

In the Linux kernel, the following vulnerability has been resolved:

drm/i915/hdcp: check streams[] bounds before overflow

The data->streams[] overflow check is done after the buffer overflow has already happened. Move the overflow check before the write.

Side note, emitting a warning splat with a backtrace might be overkill here, but prefer not changing the behaviour other than not doing the overrun.

Discovered using AI-assisted static analysis confirmed by Intel Product Security.

(cherry picked from commit 9284ab3b6e776c315883ac2611283d263c9460fd)

References

Affected packages

Azure Linux:3 / kernel

Package

Name
kernel
Purl
pkg:rpm/azure-linux/kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
6.6.150.1-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-94842.json"