Description
In the Linux kernel, the following vulnerability has been resolved:

drm/bridge: tc358767: clamp the reported AUX read size to the request

tc_aux_transfer() clamps an AUX read to the payload limit:

size_t size = min_t(size_t, DP_AUX_MAX_PAYLOAD_BYTES - 1, msg->size);

After the transfer it replaces size with the byte count the controller
reports in AUX_BYTES:

if (size)
size = FIELD_GET(AUX_BYTES, auxstatus);

AUX_BYTES is GENMASK(15, 8), so it can be up to 255. Nothing clamps it
back to the request. tc_aux_read_data() reads that many bytes into the
16-byte auxrdata stack buffer, then copies them into the caller buffer. A
reported count of 255 makes the read run to 256 bytes and overruns both.

The controller should never report more than it was asked to transfer, so
this is defense in depth rather than a live hole. The reported count is
only lightly trusted, and the check is cheap. Clamp it back to the request,
the same way ti-sn65dsi86 does in commit aca58eac52b8 ("drm/bridge:
ti-sn65dsi86: Never store more than msg->size bytes in AUX xfer").
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel stack corruption
Action: Patch Immediately
AI Analysis

Impact

The Linux kernel DRM bridge driver for the tc358767 device incorrectly trusts the controller‑reported AUX read size. After clamping the requested size, the driver later adopts the controller’s byte count without bounds checking, resulting in a 256‑byte read into a 16‑byte stack buffer. This flaw can corrupt kernel stack memory, potentially compromising system stability and integrity.

Affected Systems

Linux kernel, all releases prior to the application of the tc358767 AUX size clamp patch. No specific vendor or version list was provided beyond the generic "Linux kernel" label. System administrators should verify that the kernel image in use incorporates the relevant patch, which can be found in the upstream commit referenced in the advisory.

Risk and Exploitability

The EPSS score indicates an exploitation probability of less than 1 % and the vulnerability is not listed in the CISA KEV catalog, suggesting a low current threat level. However, as the fault resides in kernel code, any successful exploitation would affect the kernel stack and could lead to system compromise. The likely attack vector is local: an attacker with the ability to drive the drm/bridge subsystem can initiate the vulnerable AUX transfer sequence. Because the driver performs no input validation on the controller’s reported byte count, the flaw remains exploitable until the patch is applied.

Generated by OpenCVE AI on September 19, 2026 at 12:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version containing the tc358767 AUX read size clamp fix; if a kernel release is not yet available, apply the fix from the relevant commit or vendor patch set.
  • If a timely kernel update cannot be applied, disable the tc358767 DRM bridge driver, or remove the hardware module, to eliminate the vulnerable code path.
  • Restrict access to DRM devices such as /dev/dri to only privileged users and employ SELinux or AppArmor policies to limit representation and usage by unprivileged processes.

Generated by OpenCVE AI on September 19, 2026 at 12:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-120

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm/bridge: tc358767: clamp the reported AUX read size to the request tc_aux_transfer() clamps an AUX read to the payload limit: size_t size = min_t(size_t, DP_AUX_MAX_PAYLOAD_BYTES - 1, msg->size); After the transfer it replaces size with the byte count the controller reports in AUX_BYTES: if (size) size = FIELD_GET(AUX_BYTES, auxstatus); AUX_BYTES is GENMASK(15, 8), so it can be up to 255. Nothing clamps it back to the request. tc_aux_read_data() reads that many bytes into the 16-byte auxrdata stack buffer, then copies them into the caller buffer. A reported count of 255 makes the read run to 256 bytes and overruns both. The controller should never report more than it was asked to transfer, so this is defense in depth rather than a live hole. The reported count is only lightly trusted, and the check is cheap. Clamp it back to the request, the same way ti-sn65dsi86 does in commit aca58eac52b8 ("drm/bridge: ti-sn65dsi86: Never store more than msg->size bytes in AUX xfer").
Title drm/bridge: tc358767: clamp the reported AUX read size to the request
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:10:52.288Z

Reserved: 2026-09-17T15:57:05.660Z

Link: CVE-2026-93067

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:00.500

Modified: 2026-09-17T17:18:00.500

Link: CVE-2026-93067

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T05:30:16Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')