drm/panthor: reject firmware sections with oversized data
Summary
| CVE | CVE-2026-74452 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-15 13:17:49 UTC |
| Updated | 2026-08-15 13:17:49 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
drm/panthor: reject firmware sections with oversized data
In panthor_fw_load_section_entry(), the data size to copy is calculated
without validating it against the allocated section_size:
section->data.size = hdr.data.end - hdr.data.start;
If a crafted firmware sets data.size larger than the allocated memory,
this could cause a heap buffer overflow in panthor_fw_init_section_mem()
memcpy(section->mem->kmap, section->data.buf, section->data.size);
Additionally, if the section->data.size exceeds the BO size, could this
memset underflow the size calculation, leading to a massive out-of-bounds
zeroing of kernel memory?
memset(section->mem->kmap + section->data.size, 0,
panthor_kernel_bo_size(section->mem) - section->data.size);
Reject section entries whose initial data is larger than the section size. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected 2718d91816eeed03c09c8abe872e45f59078768c 0e57165ca025a67d8dfd17efd2765fdd4925fdab git |
Not specified |
| CNA |
Linux |
Linux |
affected 2718d91816eeed03c09c8abe872e45f59078768c 2a761b9be5863e1d26a584f0c2d1e114a684ed9a git |
Not specified |
| CNA |
Linux |
Linux |
affected 2718d91816eeed03c09c8abe872e45f59078768c 7f4674d986c15c74327cb6ac6e2e2afecf061e04 git |
Not specified |
| CNA |
Linux |
Linux |
affected 2718d91816eeed03c09c8abe872e45f59078768c a3caaa06809248b996254be5b47e10804a3494e2 git |
Not specified |
| CNA |
Linux |
Linux |
affected 6.10 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.10 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.103 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.44 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.1.8 7.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2-rc6 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/a3caaa06809248b996254be5b47e10804a3494e2 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/7f4674d986c15c74327cb6ac6e2e2afecf061e04 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/0e57165ca025a67d8dfd17efd2765fdd4925fdab |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/2a761b9be5863e1d26a584f0c2d1e114a684ed9a |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.