{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-64097","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-07-19T07:54:57.033Z","datePublished":"2026-07-19T15:40:03.599Z","dateUpdated":"2026-08-05T12:39:11.518Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T12:39:11.518Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Validate GPIO pin LUT table size before iterating\n\n[Why&How]\nThe GPIO pin table parsers in get_gpio_i2c_info() and\nbios_parser_get_gpio_pin_info() derive an element count from the VBIOS\ntable_header.structuresize field, then iterate over gpio_pin[] entries.\nHowever, GET_IMAGE() only validates that the table header itself fits\nwithin the BIOS image. If the VBIOS reports a structuresize larger than\nthe actual mapped data, the loop reads past the end of the BIOS image,\ncausing an out-of-bounds read.\n\nFix this by calling bios_get_image() to validate that the full claimed\nstructuresize is accessible within the BIOS image before entering the\nloop in both functions.\n\n(cherry picked from commit ba5e95b43b773ae1bf1f66ee6b31eb774e65afe3)"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The bug is reached only through the amdgpu DRM/display stack when the kernel parses VBIOS GPIO tables during connector/link setup (dc_create → link_create → get_gpio_i2c_info()/bios_parser_get_gpio_pin_info()); there is no network, Bluetooth, or USB packet path to this code.\nAC:L - Once a GPU carries a VBIOS with an inflated gpio_pin_lut structuresize, the derived loop count is fully attacker-controlled and the out-of-bounds read triggers deterministically on driver probe or display link initialization without races or layout-dependent conditions.\nPR:L - No capability checks guard the call path; any local user with ordinary access to the AMDGPU DRM device (typical video/render group membership) reaches the vulnerable parsers during normal display initialization, while a malicious VBIOS can be preinstalled via physical GPU reprogramming, supply-chain compromise, or prior privileged vbflash without ongoing root at trigger time.\nUI:N - Exploitation requires no victim interaction beyond system/driver startup; on laptops and servers with AMD GPUs the vulnerable parsing runs automatically during amdgpu module load and connector enumeration, including built-in eDP paths.\nS:U - Impact stays within kernel/GPU driver context on the same machine; corrupted VBIOS parsing does not cross a VM-host, container, or IOMMU security boundary even in SR-IOV or passthrough deployments.\nC:H - The loop performs an out-of-bounds read past the validated GPIO pin LUT when structuresize overstates the table, potentially reading adjacent kernel heap memory beyond the kmalloc'd VBIOS image and feeding attacker-influenced bytes into subsequent GPIO register-index lookups.\nI:H - Mis-parsed out-of-bounds gpio_pin_assignment entries supply data_a_reg_index and gpio_bitshift values that drive MMIO/GPIO configuration (DDC, HPD, I2C pin setup), enabling arbitrary display-engine register targeting and memory-corruption-class integrity impact rather than a benign read-only fault.\nA:H - Invalid register offsets and masks derived from out-of-bounds data can hang or fault the display subsystem and broader kernel (GPU reset, oops, or denial of service), and uncontrolled reads past the VBIOS buffer boundary can provoke crashes under memory-hardening or on marginal hardware."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/gpu/drm/amd/display/dc/bios/bios_parser2.c"],"versions":[{"version":"ae79c310b1a6f97429a5784b65f125d9cc9c95b1","lessThan":"9900f6954be779011e7c2cd42addd87baf028bc5","status":"affected","versionType":"git"},{"version":"ae79c310b1a6f97429a5784b65f125d9cc9c95b1","lessThan":"fb30a3890d62fd50a95aef684faf64a307592e42","status":"affected","versionType":"git"},{"version":"ae79c310b1a6f97429a5784b65f125d9cc9c95b1","lessThan":"67461e0c15335894cc5d3b84cda823bf8cbdc886","status":"affected","versionType":"git"},{"version":"ae79c310b1a6f97429a5784b65f125d9cc9c95b1","lessThan":"7ca695b3122297b06a3ed605bbe1cd32c85d9f5a","status":"affected","versionType":"git"},{"version":"ae79c310b1a6f97429a5784b65f125d9cc9c95b1","lessThan":"f2a4827e980ba07de4391fa84d9c39a12726bdd7","status":"affected","versionType":"git"},{"version":"ae79c310b1a6f97429a5784b65f125d9cc9c95b1","lessThan":"86d2b20644b11d21fe52c596e6e922b4590a3e3f","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/gpu/drm/amd/display/dc/bios/bios_parser2.c"],"versions":[{"version":"4.15","status":"affected"},{"version":"0","lessThan":"4.15","status":"unaffected","versionType":"semver"},{"version":"6.1.175","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.142","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.92","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","status":"unaffected","versionType":"semver"},{"version":"7.1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.15","versionEndExcluding":"6.1.175"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.15","versionEndExcluding":"6.6.142"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.15","versionEndExcluding":"6.12.92"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.15","versionEndExcluding":"6.18.34"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.15","versionEndExcluding":"7.0.11"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.15","versionEndExcluding":"7.1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/9900f6954be779011e7c2cd42addd87baf028bc5"},{"url":"https://git.kernel.org/stable/c/fb30a3890d62fd50a95aef684faf64a307592e42"},{"url":"https://git.kernel.org/stable/c/67461e0c15335894cc5d3b84cda823bf8cbdc886"},{"url":"https://git.kernel.org/stable/c/7ca695b3122297b06a3ed605bbe1cd32c85d9f5a"},{"url":"https://git.kernel.org/stable/c/f2a4827e980ba07de4391fa84d9c39a12726bdd7"},{"url":"https://git.kernel.org/stable/c/86d2b20644b11d21fe52c596e6e922b4590a3e3f"}],"title":"drm/amd/display: Validate GPIO pin LUT table size before iterating","x_generator":{"engine":"bippy-1.2.0"}}}}