drm/amd/display: Fix out-of-bounds read in dp_get_eq_aux_rd_interval()
Published Jul 1, 2026
7.1
HIGHCVSS 3.1
EPSS 0.13%
Description
[Why & How] The aux_rd_interval array in struct dc_lttpr_caps is declared with MAX_REPEATER_CNT - 1 (7) elements, indexed 0..6. However, the offset parameter passed to dp_get_eq_aux_rd_interval() can be as large as MAX_REPEATER_CNT (8) when a sink reports 8 LTTPR repeaters via DPCD. This leads to an out-of-bounds read of aux_rd_interval[7] when offset is 8.
Fix this by growing aux_rd_interval to MAX_REPEATER_CNT elements to accommodate the full range of valid repeater counts defined by the DP spec.
(cherry picked from commit a55a458a8df37a65ffda5cf721d554a8f74f6b04)
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 5.6StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.6
- Version 6.18.36StatusunaffectedConstraints<=6.18.*
- Version 7.0.13StatusunaffectedConstraints<=7.0.*
- Version 7.1StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
- ≥ 5.6 · < 6.18.36
- ≥ 6.19 · < 7.0.13
- 7.1
- 7.1
- 7.1
- 7.1
- 7.1
- 7.1
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (9)
- https://access.redhat.com/security/cve/CVE-2026-53330 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2495957 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-40964 Advisory
- https://git.kernel.org/stable/c/454d3b3d499c18373f8960d31aea48338a3ca9e0 Patch
- https://git.kernel.org/stable/c/dc1490927d79fe9621e29f4a4f5d7b5ccb6aea3e Patch
- https://git.kernel.org/stable/c/e8b4d37eba05141ee01794fc6b7f2da808cee83b Patch
- https://lore.kernel.org/linux-cve-announce/2026070142-CVE-2026-53330-0e20@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2026-53330
- https://www.cve.org/CVERecord?id=CVE-2026-53330
Change history (0)
No recorded changes yet.