CVE-2026-98181: drm/gud: fix out-of-bounds write in gud_plane_atomic_check()
Published Oct 6, 2026
·Updated
drm/gud: fix out-of-bounds write in gudplaneatomiccheck()
Affected Software
1 affected component
Linux Linux kernel
Event History
Oct 6, 2026
CVE Published
via MITRE·08:44 AM
Data Sourced
via MITRE·08:44 AM
Description
Data Sourced
via NVD·09:18 AM
Description
Oct 7, 2026
Data Sourced
via Microsoft·08:20 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
An attacker needs to present a USB device to the affected system. The device can trigger the flaw by advertising the maximum number of supported properties.
2
Which systems are exposed?
Systems are exposed when the Linux kernel's drm/gud code processes a GUD USB device's plane and connector properties. The issue occurs during the plane property handling path.
3
What condition causes the out-of-bounds write?
The vulnerable indexing advances twice per plane-property iteration because the running property count is incremented while also being combined with the loop index. With 2 connector properties and 32 plane properties, the final write reaches index 64 of a 64-entry allocation, beyond the valid 0–63 range.