drm/amd/display: Clamp VBIOS HDMI retimer register count to array size
Published Jun 25, 2026
7.8
HIGHCVSS 3.1
EPSS 0.13%
Description
[Why & How] The VBIOS integrated info tables (v1_11 and v2_1) contain HdmiRegNum and Hdmi6GRegNum fields that are used as loop bounds when copying retimer I2C register settings into fixed-size arrays (dp*_ext_hdmi_reg_settings[9] and dp*_ext_hdmi_6g_reg_settings[3]). These u8 fields are not validated before use, so a malformed VBIOS can specify values up to 255, causing an out-of-bounds heap write during driver probe.
Clamp each register count to the destination array size using min_t() before the copy loops, in both get_integrated_info_v11() and get_integrated_info_v2_1().
(cherry picked from commit 5a7f0ef90195940c54b0f5bb85b87da55f038c69)
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 4.15StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<4.15
- Version 5.15.210StatusunaffectedConstraints<=5.15.*
- Version 6.1.176StatusunaffectedConstraints<=6.1.*
- Version 6.12.94StatusunaffectedConstraints<=6.12.*
- Version 6.18.36StatusunaffectedConstraints<=6.18.*
- Version 6.6.143StatusunaffectedConstraints<=6.6.*
- Version 7.0.13StatusunaffectedConstraints<=7.0.*
- Version 7.1StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 4.15 · < 5.15.210
- ≥ 5.16 · < 6.1.176
- ≥ 6.2 · < 6.6.143
- ≥ 6.7 · < 6.12.94
- ≥ 6.13 · < 6.18.36
- ≥ 6.19 · < 7.0.13
- 7.1
- 7.1
- 7.1
- 7.1
- 7.1
- 7.1
No data.
Red Hat Enterprise Linux 10
kernel-0:6.12.0-211.49.1.el10_2
Fixed · RHSA-2026:57251
Red Hat Enterprise Linux 8
kernel-0:4.18.0-553.156.1.el8_10
Fixed · RHSA-2026:55764
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-553.156.1.rt7.497.el8_10
Fixed · RHSA-2026:55765
Red Hat Enterprise Linux 9
kernel-0:5.14.0-687.41.1.el9_8
Fixed · RHSA-2026:57252
Red Hat Enterprise Linux 9
kernel-0:5.14.0-687.41.1.el9_8
Fixed · RHSA-2026:57252
Red Hat Enterprise Linux 6
kernel
Under investigation
Red Hat Enterprise Linux 7
kernel
Affected
Red Hat Enterprise Linux 7
kernel-rt
Affected
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel-0:6.12.0-211.49.1.el10_2 | Fixed | RHSA-2026:57251 |
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-553.156.1.el8_10 | Fixed | RHSA-2026:55764 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-553.156.1.rt7.497.el8_10 | Fixed | RHSA-2026:55765 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-687.41.1.el9_8 | Fixed | RHSA-2026:57252 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-687.41.1.el9_8 | Fixed | RHSA-2026:57252 |
| Red Hat Enterprise Linux 6 | kernel | Under investigation | n/a |
| Red Hat Enterprise Linux 7 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (12)
- https://access.redhat.com/security/cve/CVE-2026-53136 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2492768 Issue Tracking
- https://git.kernel.org/stable/c/029571d51140650783be4fb98fe7cb4754752086 Patch
- https://git.kernel.org/stable/c/3f32d52ec604c659725d865cf8cc6a17a33f9c6a Patch
- https://git.kernel.org/stable/c/4d1c3c26c2ab1842e139e61983395d64bd2e518b Patch
- https://git.kernel.org/stable/c/5f8b39452fb16f507c9e4d8b4a83ce27e893307c Patch
- https://git.kernel.org/stable/c/8aaa7e317fbd4beb9c6a9f77aa4cf52fae78b117 Patch
- https://git.kernel.org/stable/c/d6be8e59af412623e3d874be3a048406c0edfe60 Patch
- https://git.kernel.org/stable/c/fb0707ce00eef4e2d60c3020e1c0432739703e4a Patch
- https://lore.kernel.org/linux-cve-announce/2026062543-CVE-2026-53136-b8ab@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2026-53136
- https://www.cve.org/CVERecord?id=CVE-2026-53136
Change history (0)
No recorded changes yet.