SB20260816273 - Improper input validation in Linux kernel drm vc4 driver



SB20260816273 - Improper input validation in Linux kernel drm vc4 driver

Published: August 16, 2026

Security Bulletin ID SB20260816273
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper input validation (CVE-ID: CVE-2026-74453)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper input validation in validate_tile_binning_config when processing tile binning configurations with oversized tile state arrays. A local user can submit a crafted tile binning configuration that leaves no room for the tile allocation pool to cause a denial of service.

The tile state data array size is derived from tile count fields and shares the same buffer slot with the tile allocation pool.


Remediation

Install update from vendor's website.