SB20260917154 - Improper Null Termination in Linux kernel drm gud driver
Published: September 17, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper Null Termination (CVE-ID: CVE-2026-89817)
CWE-ID: CWE-170 - Improper Null Termination
CVSSv4: 0 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows an attacker with physical access to perform an out-of-bounds read.
The vulnerability exists due to improper null termination in gud_connector_add_tv_mode() when processing TV mode names received from a USB device. An attacker with physical access can provide TV mode names that are not NUL-terminated to perform an out-of-bounds read.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/08c8ec28547987e55a90c662f8795e05c2925498
- https://git.kernel.org/stable/c/500cb24cd61bad8a2747ddfc49b7034899c82d94
- https://git.kernel.org/stable/c/6ea61f1d4cbaa0db937e31bffc041fb8afeacf52
- https://git.kernel.org/stable/c/89210cb5ff8fdbe055c97ac688be2268f6c815ae
- https://git.kernel.org/stable/c/9096edfd6f2edbc79612b482547e0972edbcfe4b
- https://git.kernel.org/stable/c/b86438a5c6b0250ccb07dd380184d1e70e0dea6c
- https://git.kernel.org/stable/c/d0f3312f7800eb0e00d1264f66104c788f43dd69