CVE-2026-53329
Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
01/07/2026
Última modificación:
23/07/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
drm/amd/display: Use krealloc_array() in dal_vector_reserve()<br />
<br />
[Why & How]<br />
dal_vector_reserve() computes the allocation size as<br />
"capacity * vector->struct_size" using uint32_t arithmetic, which can<br />
silently wrap to a small value on overflow. This would cause krealloc to<br />
return a smaller buffer than expected, leading to heap overflows on<br />
subsequent vector appends.<br />
<br />
Replace krealloc() with krealloc_array() which performs an internal<br />
overflow check and returns NULL on wrap, preventing the issue.<br />
<br />
(cherry picked from commit 37668568641ccc4cc1dbca4923d0a16609dd5707)
Impacto
Puntuación base 3.x
7.00
Gravedad 3.x
ALTA
Productos y versiones vulnerables
| CPE | Desde | Hasta |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 4.15 (incluyendo) | 5.10.260 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.11 (incluyendo) | 5.15.210 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.16 (incluyendo) | 6.1.176 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.2 (incluyendo) | 6.6.143 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (incluyendo) | 6.12.94 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (incluyendo) | 6.18.36 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.19 (incluyendo) | 7.0.13 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:* |
Para consultar la lista completa de nombres de CPE con productos y versiones, ver esta página
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/201151e120f0062bcda21cad5d007b82725ad23b
- https://git.kernel.org/stable/c/31180638a33acad12c863132704a76536fb66211
- https://git.kernel.org/stable/c/9540b0a4d13e4ede64ae1197d66a176d2149daa9
- https://git.kernel.org/stable/c/a914aa802669e073f014dae2e5708633b5cecd34
- https://git.kernel.org/stable/c/b15825deac1acff72638bbc8f05b89ceef8dfb13
- https://git.kernel.org/stable/c/da48bc4461b8a5ebfb9264c9b191a701d8e99009
- https://git.kernel.org/stable/c/de988c7a31f0774f07894cfe4802996f318e2870
- https://git.kernel.org/stable/c/e09689286385a66311ac6922af95339d7a3cef8d



