Impact
The DRM/gud connector in the Linux kernel reads TV mode names supplied by an attached USB device into a fixed-size buffer without ensuring that each name is terminated with a NUL character. The code then passes pointers to these strings to a routine that calls strlen(), which can read past the end of the slot and possibly beyond the allocation. This out‑of‑bounds read could expose kernel or user memory, leading to the disclosure of sensitive data. No write or execute privileges are provided, so the vulnerability is limited to information disclosure.
Affected Systems
All Linux kernel builds that include the drm/gud module before the patch are affected. This includes mainstream kernel releases with DRM/gud enabled as well as embedded or custom kernel builds that incorporate the DRM stack. The vulnerability is present wherever the drm/gud driver is loaded and processes TV mode names from a USB device.
Risk and Exploitability
The EPSS score of less than 1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the likely attack vector is local, requiring an attacker to control a USB device that supplies malformed TV mode names and trigger the driver to read them. The vulnerability provides only data disclosure and does not allow credential escalation, code execution, or denial of service.
OpenCVE Enrichment
Debian DLA
Debian DSA