In the Linux kernel, the following vulnerability has been resolved:
drm/virtio: bound EDID block reads to the response buffer
virtio_get_edid_block() validates the read offset only against the
device-supplied resp->size field, never against the fixed-size resp->edid
array. The EDID block index is driven by the device-supplied extension
count, so a malicious virtio-gpu backend can advertise a large size
together with a high block count and read far past the array into adjacent
kernel memory, which is then surfaced in the parsed EDID (an out-of-bounds
read / info leak).
Also reject any read whose end exceeds the size of the edid array.
Conforming EDID responses stay within the array and are unaffected.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-10 13:20
Updated : 2026-08-23 13:16
NVD link : CVE-2026-68255
Mitre link : CVE-2026-68255
CVE.ORG link : CVE-2026-68255
JSON object : View
Products Affected
No product.
CWE
No CWE.
