Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-46263

Gravedad CVSS v3.1:
ALTA
Tipo:
CWE-125 Lectura fuera de límites
Fecha de publicación:
03/06/2026
Última modificación:
09/06/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> drm/amd/display: Fix out-of-bounds stream encoder index v3<br /> <br /> eng_id can be negative and that stream_enc_regs[]<br /> can be indexed out of bounds.<br /> <br /> eng_id is used directly as an index into stream_enc_regs[], which has<br /> only 5 entries. When eng_id is 5 (ENGINE_ID_DIGF) or negative, this can<br /> access memory past the end of the array.<br /> <br /> Add a bounds check using ARRAY_SIZE() before using eng_id as an index.<br /> The unsigned cast also rejects negative values.<br /> <br /> This avoids out-of-bounds access.<br /> <br /> Fixes the below smatch error:<br /> dcn*_resource.c: stream_encoder_create() may index<br /> stream_enc_regs[eng_id] out of bounds (size 5).<br /> <br /> drivers/gpu/drm/amd/amdgpu/../display/dc/resource/dcn351/dcn351_resource.c<br /> 1246 static struct stream_encoder *dcn35_stream_encoder_create(<br /> 1247 enum engine_id eng_id,<br /> 1248 struct dc_context *ctx)<br /> 1249 {<br /> <br /> ...<br /> <br /> 1255<br /> 1256 /* Mapping of VPG, AFMT, DME register blocks to DIO block instance */<br /> 1257 if (eng_id

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.9 (incluyendo) 6.12.75 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (incluyendo) 6.18.14 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.19 (incluyendo) 6.19.4 (excluyendo)