CVE-2026-98181

Source
https://cve.org/CVERecord?id=CVE-2026-98181
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98181.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98181
Downstream
Published
2026-10-06T08:44:24Z
Modified
2026-10-07T02:47:29Z
Summary
drm/gud: fix out-of-bounds write in gud_plane_atomic_check()
Details

In the Linux kernel, the following vulnerability has been resolved:

drm/gud: fix out-of-bounds write in gud_plane_atomic_check()

The plane property loop uses req->properties[num_properties + i] as write index while simultaneously incrementing num_properties inside the loop. At iteration i, num_properties has also incremented by i, so the write is done at initial_num_properties + 2*i, skipping every other index and advancing by 2 per iteration.

With just 2 connector and 32 plane properties the last write happens at index 64, one slot past the end of the 64-slot (indices 0–63) allocation. A USB device can trigger OOB by advertising the maximum number of properties.

Fix by dropping the redundant + i; num_properties is already the correct running index, as gud_connector_fill_properties() fills the preceding slots.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98181.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
40e1a70b4aedf2859a1829991b48ef0ebe650bf2
Fixed
ee04903fe6a098160d20dde4fc5af4cb42846735
Fixed
4153a9e008f2512bd3cf90a319436865847369b9
Fixed
5f5e565410b4987e9663f599f9ab0c350f8338d4
Fixed
7e630edb22088df7aa0d55b02237a71e4c9a523d
Fixed
2c92af27ad23e2fbc0367b11a9027d36d94ef4b3
Fixed
ea57100955c1c2a525ba1a98c18d9a05b25aeedb
Fixed
59ced288fcba9e91bd38e61a972ad782c4edb7d0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98181.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.13.0
Fixed
5.15.222
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.189
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.158
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98181.json"