CVE-2026-89817

In the Linux kernel, the following vulnerability has been resolved: drm/gud: NUL-terminate TV mode names read from the device gud_connector_add_tv_mode() reads a buffer of fixed-size mode names from the USB device and passes pointers into it to drm_mode_create_tv_properties_legacy(), which calls strlen() on each one. Nothing guarantees the device NUL-terminates a name, so strlen() can run past the end of a slot and, for the last mode, past the end of the allocation. Terminate each name at the end of its slot before use.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-09-16 11:16

Updated : 2026-09-16 11:16


NVD link : CVE-2026-89817

Mitre link : CVE-2026-89817

CVE.ORG link : CVE-2026-89817


JSON object : View

Products Affected

No product.

CWE

No CWE.