Out-of-bounds read in Linux kernel - CVE-2026-64546
Published: July 28, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to out-of-bounds read in drm_parse_tiled_block() when parsing a crafted DisplayID tiled-display block in EDID data. A local user can supply crafted EDID data with a truncated tiled-display block to disclose sensitive information.
The issue is triggered when the tiled-display block declares a small payload length near the end of a DisplayID extension.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-64546
linux (Debian package) - update to 6.12.100-1
External References
- https://git.kernel.org/stable/c/157727131ce8a52d8d9bc676c372ef82db6436c4
- https://git.kernel.org/stable/c/4137e1ecec9c8cb6c4fcee28ffabbbc7409eb7fb
- https://git.kernel.org/stable/c/4f5484d25f85ad6c989bad5f6a43450cecfcfd28
- https://git.kernel.org/stable/c/9acd5c1ddc17ca4c5ffa0c373e3fdf480506e061
- https://git.kernel.org/stable/c/9cc0f8e63e8c34cf43def35cbd305ba711181a1f
- https://git.kernel.org/stable/c/bfa05d89dc3ca3fb1a9099ef5185549a5ec8490d
- https://git.kernel.org/stable/c/c4ab04ca1bbf87eefa9fec5c80e1880450d2e7c0
- https://git.kernel.org/stable/c/faaa1e1155833e7d4ce7e3cfaf64c0d636b190db