CVE-2026-68277

Source
https://cve.org/CVERecord?id=CVE-2026-68277
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68277.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-68277
Downstream
Published
2026-08-10T12:01:53.085Z
Modified
2026-08-12T04:19:22.250317965Z
Summary
drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers
Details

In the Linux kernel, the following vulnerability has been resolved:

drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers

Three sideband reply parsers read 16-bit fields as:

val = (raw->msg[idx] << 8) | (raw->msg[idx+1]);

and check bounds only after the fact. When idx == raw->curlen, raw->msg[idx+1] reads one byte past the received message data into the following struct fields (curchunklen, curchunkidx, curlen).

Affected functions: - drmdpsidebandparseenumpathresourcesack() fullpayloadbwnumber and availpayloadbwnumber fields - drmdpsidebandparseallocatepayloadack() allocatedpbn field - drmdpsidebandparsequerypayloadack() allocated_pbn field

Fix by using a single combined check (idx + 2 > curlen) before each 2-byte read. Since the check is strictly tighter than idx > curlen, no separate step is needed.

[added fixes tag]

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68277.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ad7f8a1f9ced7f049f9b66d588723f243a7034cd
Fixed
bdf0508b1e6785d4a8982c637e97e68d60b47d7b
Fixed
0bcd7675c69a2462a8531fcd9e4d096e9c7ec5df
Fixed
d5c70523cafa26ad2c7a37b612849abe2683baa8
Fixed
68a624416d1dd481b3e5b7ea0e8a070a9b8a2c73
Fixed
6b89ba3dba2f583626fb693e47e951ffb8bf591f

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68277.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.17.0
Fixed
6.6.148
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.101
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.42
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68277.json"