In the Linux kernel, the following vulnerability has been resolved:
drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers
Three sideband reply parsers read 16-bit fields as:
val = (raw->msg[idx] << 8) | (raw->msg[idx+1]);
and check bounds only after the fact. When idx == raw->curlen, raw->msg[idx+1] reads one byte past the received message data into the following struct fields (curchunklen, curchunkidx, curlen).
Affected functions: - drmdpsidebandparseenumpathresourcesack() fullpayloadbwnumber and availpayloadbwnumber fields - drmdpsidebandparseallocatepayloadack() allocatedpbn field - drmdpsidebandparsequerypayloadack() allocated_pbn field
Fix by using a single combined check (idx + 2 > curlen) before each 2-byte read. Since the check is strictly tighter than idx > curlen, no separate step is needed.
[added fixes tag]
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68277.json",
"cna_assigner": "Linux"
}