{"api_version":"1","generated_at":"2026-08-02T01:11:17+00:00","cve":"CVE-2026-64546","urls":{"html":"https://cve.report/CVE-2026-64546","api":"https://cve.report/api/cve/CVE-2026-64546.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-64546","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-64546"},"summary":{"title":"drm/edid: fix OOB read in drm_parse_tiled_block()","description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/edid: fix OOB read in drm_parse_tiled_block()\n\ndrm_parse_tiled_block() casts the DisplayID block to a\nstruct displayid_tiled_block and reads the full fixed layout up to\ntile->topology_id[7] without checking block->num_bytes. The DisplayID\niterator only validates the declared payload length, so a crafted EDID\ncan advertise a tiled-display block (tag DATA_BLOCK_TILED_DISPLAY, or\nDATA_BLOCK_2_TILED_DISPLAY_TOPOLOGY for v2.0) with a small num_bytes at\nthe end of a DisplayID extension. The read then runs past the end of the\nexact-sized kmemdup()'d EDID allocation, a heap out-of-bounds read.\n\nReject blocks shorter than the spec's 22-byte tiled payload before\nreading the fixed struct, as drm_parse_vesa_mso_data() already does.\n\n  BUG: KASAN: slab-out-of-bounds in drm_edid_connector_update\n  Read of size 2 at addr ffff888010077700 by task exploit/147\n   dump_stack_lvl (lib/dump_stack.c:94 ...)\n   print_report (mm/kasan/report.c:378 ...)\n   kasan_report (mm/kasan/report.c:595)\n   drm_edid_connector_update (drivers/gpu/drm/drm_edid.c:7581)\n   bochs_connector_helper_get_modes (drivers/gpu/drm/tiny/bochs.c:574)\n   drm_helper_probe_single_connector_modes (drivers/gpu/drm/drm_probe_helper.c:426)\n   status_store (drivers/gpu/drm/drm_sysfs.c:219)\n   ...\n   vfs_write (fs/read_write.c:595 fs/read_write.c:688)\n   ksys_write (fs/read_write.c:740)","state":"PUBLISHED","assigner":"Linux","published_at":"2026-07-27 21:17:07","updated_at":"2026-07-30 06:25:58"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"7.1","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"7.1","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","data":{"baseScore":7.1,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/c4ab04ca1bbf87eefa9fec5c80e1880450d2e7c0","name":"https://git.kernel.org/stable/c/c4ab04ca1bbf87eefa9fec5c80e1880450d2e7c0","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/4f5484d25f85ad6c989bad5f6a43450cecfcfd28","name":"https://git.kernel.org/stable/c/4f5484d25f85ad6c989bad5f6a43450cecfcfd28","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/9acd5c1ddc17ca4c5ffa0c373e3fdf480506e061","name":"https://git.kernel.org/stable/c/9acd5c1ddc17ca4c5ffa0c373e3fdf480506e061","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/9cc0f8e63e8c34cf43def35cbd305ba711181a1f","name":"https://git.kernel.org/stable/c/9cc0f8e63e8c34cf43def35cbd305ba711181a1f","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/157727131ce8a52d8d9bc676c372ef82db6436c4","name":"https://git.kernel.org/stable/c/157727131ce8a52d8d9bc676c372ef82db6436c4","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/4137e1ecec9c8cb6c4fcee28ffabbbc7409eb7fb","name":"https://git.kernel.org/stable/c/4137e1ecec9c8cb6c4fcee28ffabbbc7409eb7fb","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/bfa05d89dc3ca3fb1a9099ef5185549a5ec8490d","name":"https://git.kernel.org/stable/c/bfa05d89dc3ca3fb1a9099ef5185549a5ec8490d","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/faaa1e1155833e7d4ce7e3cfaf64c0d636b190db","name":"https://git.kernel.org/stable/c/faaa1e1155833e7d4ce7e3cfaf64c0d636b190db","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-64546","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64546","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 40d9b043a89e2301e1f97ade055a73ecc28e9afe c4ab04ca1bbf87eefa9fec5c80e1880450d2e7c0 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 40d9b043a89e2301e1f97ade055a73ecc28e9afe 9acd5c1ddc17ca4c5ffa0c373e3fdf480506e061 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 40d9b043a89e2301e1f97ade055a73ecc28e9afe 157727131ce8a52d8d9bc676c372ef82db6436c4 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 40d9b043a89e2301e1f97ade055a73ecc28e9afe bfa05d89dc3ca3fb1a9099ef5185549a5ec8490d git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 40d9b043a89e2301e1f97ade055a73ecc28e9afe 4f5484d25f85ad6c989bad5f6a43450cecfcfd28 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 40d9b043a89e2301e1f97ade055a73ecc28e9afe 9cc0f8e63e8c34cf43def35cbd305ba711181a1f git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 40d9b043a89e2301e1f97ade055a73ecc28e9afe 4137e1ecec9c8cb6c4fcee28ffabbbc7409eb7fb git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 40d9b043a89e2301e1f97ade055a73ecc28e9afe faaa1e1155833e7d4ce7e3cfaf64c0d636b190db git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 3.19","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 3.19 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.10.261 5.10.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.15.212 5.15.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.1.178 6.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.6.145 6.6.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.97 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.40 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1.5 7.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2-rc1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"64546","cve":"CVE-2026-64546","epss":"0.001260000","percentile":"0.026350000","score_date":"2026-08-01","updated_at":"2026-08-02 00:11:14"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/gpu/drm/drm_edid.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"c4ab04ca1bbf87eefa9fec5c80e1880450d2e7c0","status":"affected","version":"40d9b043a89e2301e1f97ade055a73ecc28e9afe","versionType":"git"},{"lessThan":"9acd5c1ddc17ca4c5ffa0c373e3fdf480506e061","status":"affected","version":"40d9b043a89e2301e1f97ade055a73ecc28e9afe","versionType":"git"},{"lessThan":"157727131ce8a52d8d9bc676c372ef82db6436c4","status":"affected","version":"40d9b043a89e2301e1f97ade055a73ecc28e9afe","versionType":"git"},{"lessThan":"bfa05d89dc3ca3fb1a9099ef5185549a5ec8490d","status":"affected","version":"40d9b043a89e2301e1f97ade055a73ecc28e9afe","versionType":"git"},{"lessThan":"4f5484d25f85ad6c989bad5f6a43450cecfcfd28","status":"affected","version":"40d9b043a89e2301e1f97ade055a73ecc28e9afe","versionType":"git"},{"lessThan":"9cc0f8e63e8c34cf43def35cbd305ba711181a1f","status":"affected","version":"40d9b043a89e2301e1f97ade055a73ecc28e9afe","versionType":"git"},{"lessThan":"4137e1ecec9c8cb6c4fcee28ffabbbc7409eb7fb","status":"affected","version":"40d9b043a89e2301e1f97ade055a73ecc28e9afe","versionType":"git"},{"lessThan":"faaa1e1155833e7d4ce7e3cfaf64c0d636b190db","status":"affected","version":"40d9b043a89e2301e1f97ade055a73ecc28e9afe","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/gpu/drm/drm_edid.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"3.19"},{"lessThan":"3.19","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"5.10.*","status":"unaffected","version":"5.10.261","versionType":"semver"},{"lessThanOrEqual":"5.15.*","status":"unaffected","version":"5.15.212","versionType":"semver"},{"lessThanOrEqual":"6.1.*","status":"unaffected","version":"6.1.178","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.145","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.97","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.40","versionType":"semver"},{"lessThanOrEqual":"7.1.*","status":"unaffected","version":"7.1.5","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2-rc1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.10.261","versionStartIncluding":"3.19","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.15.212","versionStartIncluding":"3.19","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.1.178","versionStartIncluding":"3.19","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.145","versionStartIncluding":"3.19","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.97","versionStartIncluding":"3.19","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.40","versionStartIncluding":"3.19","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.5","versionStartIncluding":"3.19","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2-rc1","versionStartIncluding":"3.19","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/edid: fix OOB read in drm_parse_tiled_block()\n\ndrm_parse_tiled_block() casts the DisplayID block to a\nstruct displayid_tiled_block and reads the full fixed layout up to\ntile->topology_id[7] without checking block->num_bytes. The DisplayID\niterator only validates the declared payload length, so a crafted EDID\ncan advertise a tiled-display block (tag DATA_BLOCK_TILED_DISPLAY, or\nDATA_BLOCK_2_TILED_DISPLAY_TOPOLOGY for v2.0) with a small num_bytes at\nthe end of a DisplayID extension. The read then runs past the end of the\nexact-sized kmemdup()'d EDID allocation, a heap out-of-bounds read.\n\nReject blocks shorter than the spec's 22-byte tiled payload before\nreading the fixed struct, as drm_parse_vesa_mso_data() already does.\n\n  BUG: KASAN: slab-out-of-bounds in drm_edid_connector_update\n  Read of size 2 at addr ffff888010077700 by task exploit/147\n   dump_stack_lvl (lib/dump_stack.c:94 ...)\n   print_report (mm/kasan/report.c:378 ...)\n   kasan_report (mm/kasan/report.c:595)\n   drm_edid_connector_update (drivers/gpu/drm/drm_edid.c:7581)\n   bochs_connector_helper_get_modes (drivers/gpu/drm/tiny/bochs.c:574)\n   drm_helper_probe_single_connector_modes (drivers/gpu/drm/drm_probe_helper.c:426)\n   status_store (drivers/gpu/drm/drm_sysfs.c:219)\n   ...\n   vfs_write (fs/read_write.c:595 fs/read_write.c:688)\n   ksys_write (fs/read_write.c:740)"}],"metrics":[{"cvssV3_1":{"baseScore":7.1,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","version":"3.1"}}],"providerMetadata":{"dateUpdated":"2026-07-30T06:06:38.661Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/c4ab04ca1bbf87eefa9fec5c80e1880450d2e7c0"},{"url":"https://git.kernel.org/stable/c/9acd5c1ddc17ca4c5ffa0c373e3fdf480506e061"},{"url":"https://git.kernel.org/stable/c/157727131ce8a52d8d9bc676c372ef82db6436c4"},{"url":"https://git.kernel.org/stable/c/bfa05d89dc3ca3fb1a9099ef5185549a5ec8490d"},{"url":"https://git.kernel.org/stable/c/4f5484d25f85ad6c989bad5f6a43450cecfcfd28"},{"url":"https://git.kernel.org/stable/c/9cc0f8e63e8c34cf43def35cbd305ba711181a1f"},{"url":"https://git.kernel.org/stable/c/4137e1ecec9c8cb6c4fcee28ffabbbc7409eb7fb"},{"url":"https://git.kernel.org/stable/c/faaa1e1155833e7d4ce7e3cfaf64c0d636b190db"}],"title":"drm/edid: fix OOB read in drm_parse_tiled_block()","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-64546","datePublished":"2026-07-27T20:10:37.217Z","dateReserved":"2026-07-19T15:36:31.795Z","dateUpdated":"2026-07-30T06:06:38.661Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-07-27 21:17:07","lastModifiedDate":"2026-07-30 06:25:58","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.2}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"64546","Ordinal":"1","Title":"drm/edid: fix OOB read in drm_parse_tiled_block()","CVE":"CVE-2026-64546","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"64546","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/edid: fix OOB read in drm_parse_tiled_block()\n\ndrm_parse_tiled_block() casts the DisplayID block to a\nstruct displayid_tiled_block and reads the full fixed layout up to\ntile->topology_id[7] without checking block->num_bytes. The DisplayID\niterator only validates the declared payload length, so a crafted EDID\ncan advertise a tiled-display block (tag DATA_BLOCK_TILED_DISPLAY, or\nDATA_BLOCK_2_TILED_DISPLAY_TOPOLOGY for v2.0) with a small num_bytes at\nthe end of a DisplayID extension. The read then runs past the end of the\nexact-sized kmemdup()'d EDID allocation, a heap out-of-bounds read.\n\nReject blocks shorter than the spec's 22-byte tiled payload before\nreading the fixed struct, as drm_parse_vesa_mso_data() already does.\n\n  BUG: KASAN: slab-out-of-bounds in drm_edid_connector_update\n  Read of size 2 at addr ffff888010077700 by task exploit/147\n   dump_stack_lvl (lib/dump_stack.c:94 ...)\n   print_report (mm/kasan/report.c:378 ...)\n   kasan_report (mm/kasan/report.c:595)\n   drm_edid_connector_update (drivers/gpu/drm/drm_edid.c:7581)\n   bochs_connector_helper_get_modes (drivers/gpu/drm/tiny/bochs.c:574)\n   drm_helper_probe_single_connector_modes (drivers/gpu/drm/drm_probe_helper.c:426)\n   status_store (drivers/gpu/drm/drm_sysfs.c:219)\n   ...\n   vfs_write (fs/read_write.c:595 fs/read_write.c:688)\n   ksys_write (fs/read_write.c:740)","Type":"Description","Title":"drm/edid: fix OOB read in drm_parse_tiled_block()"}]}}}