In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Use kreallocarray() in dalvector_reserve()
[Why & How] dalvectorreserve() computes the allocation size as "capacity * vector->structsize" using uint32t arithmetic, which can silently wrap to a small value on overflow. This would cause krealloc to return a smaller buffer than expected, leading to heap overflows on subsequent vector appends.
Replace krealloc() with krealloc_array() which performs an internal overflow check and returns NULL on wrap, preventing the issue.
(cherry picked from commit 37668568641ccc4cc1dbca4923d0a16609dd5707)
{
"cna_assigner": "Linux",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53329.json"
}