{"api_version":"1","generated_at":"2026-08-14T20:54:05+00:00","cve":"CVE-2026-68262","urls":{"html":"https://cve.report/CVE-2026-68262","api":"https://cve.report/api/cve/CVE-2026-68262.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-68262","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-68262"},"summary":{"title":"drm/imagination: Fix user array stride in pvr_set_uobj_array()","description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/imagination: Fix user array stride in pvr_set_uobj_array()\n\npvr_set_uobj_array() copies an array of kernel objects to a userspace\narray whose element size is described by out->stride. When out->stride\nis different from the kernel object size, the slow path advances the\nuserspace pointer by the kernel object size and the kernel pointer by the\nuserspace stride.\n\nThis reverses the intended layout. For larger userspace strides, later\ncopies read from the wrong kernel addresses. For smaller userspace\nstrides, later copies are written at the wrong userspace offsets. The\npadding clear is also done only for the first element instead of the\npadding area for each element.\n\nAdvance the userspace pointer by out->stride and the kernel pointer by\nobj_size, and clear per-element padding while the current userspace\npointer is still available.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-08-10 13:20:14","updated_at":"2026-08-13 23:17:26"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"7.1","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"7.1","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","data":{"baseScore":7.1,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/09beaf4aec05b0525f2153dce693f3eb3166697a","name":"https://git.kernel.org/stable/c/09beaf4aec05b0525f2153dce693f3eb3166697a","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/bbebc39a70f6fc9b02637c8624349e30325873cb","name":"https://git.kernel.org/stable/c/bbebc39a70f6fc9b02637c8624349e30325873cb","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/b983a35dad3701399c692d7c6eb57d8b6ffc0929","name":"https://git.kernel.org/stable/c/b983a35dad3701399c692d7c6eb57d8b6ffc0929","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/8dc8f3f4c2382fb7d1b1986ba8f33a2466cd3d7a","name":"https://git.kernel.org/stable/c/8dc8f3f4c2382fb7d1b1986ba8f33a2466cd3d7a","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-68262","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-68262","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected f99f5f3ea7efd54ba0529c4f2d7c72712918a522 bbebc39a70f6fc9b02637c8624349e30325873cb git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected f99f5f3ea7efd54ba0529c4f2d7c72712918a522 b983a35dad3701399c692d7c6eb57d8b6ffc0929 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected f99f5f3ea7efd54ba0529c4f2d7c72712918a522 09beaf4aec05b0525f2153dce693f3eb3166697a git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected f99f5f3ea7efd54ba0529c4f2d7c72712918a522 8dc8f3f4c2382fb7d1b1986ba8f33a2466cd3d7a git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.8","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.8 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.101 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.42 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1.6 7.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2-rc2 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"68262","cve":"CVE-2026-68262","epss":"0.001750000","percentile":"0.072440000","score_date":"2026-08-13","updated_at":"2026-08-14 00:07:35"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/gpu/drm/imagination/pvr_drv.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"bbebc39a70f6fc9b02637c8624349e30325873cb","status":"affected","version":"f99f5f3ea7efd54ba0529c4f2d7c72712918a522","versionType":"git"},{"lessThan":"b983a35dad3701399c692d7c6eb57d8b6ffc0929","status":"affected","version":"f99f5f3ea7efd54ba0529c4f2d7c72712918a522","versionType":"git"},{"lessThan":"09beaf4aec05b0525f2153dce693f3eb3166697a","status":"affected","version":"f99f5f3ea7efd54ba0529c4f2d7c72712918a522","versionType":"git"},{"lessThan":"8dc8f3f4c2382fb7d1b1986ba8f33a2466cd3d7a","status":"affected","version":"f99f5f3ea7efd54ba0529c4f2d7c72712918a522","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/gpu/drm/imagination/pvr_drv.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"6.8"},{"lessThan":"6.8","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.101","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.42","versionType":"semver"},{"lessThanOrEqual":"7.1.*","status":"unaffected","version":"7.1.6","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2-rc2","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.101","versionStartIncluding":"6.8","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.42","versionStartIncluding":"6.8","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.6","versionStartIncluding":"6.8","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2-rc2","versionStartIncluding":"6.8","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/imagination: Fix user array stride in pvr_set_uobj_array()\n\npvr_set_uobj_array() copies an array of kernel objects to a userspace\narray whose element size is described by out->stride. When out->stride\nis different from the kernel object size, the slow path advances the\nuserspace pointer by the kernel object size and the kernel pointer by the\nuserspace stride.\n\nThis reverses the intended layout. For larger userspace strides, later\ncopies read from the wrong kernel addresses. For smaller userspace\nstrides, later copies are written at the wrong userspace offsets. The\npadding clear is also done only for the first element instead of the\npadding area for each element.\n\nAdvance the userspace pointer by out->stride and the kernel pointer by\nobj_size, and clear per-element padding while the current userspace\npointer is still available."}],"metrics":[{"cvssV3_1":{"baseScore":7.1,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:L - The bug is reached through the DRM_IOCTL_PVR_DEV_QUERY ioctl on the Imagination PowerVR render node (/dev/dri/renderD*), requiring local access to the device file; there is no remote or adjacent path.\nAC:L - The attacker fully controls the drm_pvr_obj_array stride and count fields passed to the ioctl, so the mis-advanced kernel pointer and the resulting out-of-bounds read occur deterministically on every call, with no race or unpredictable precondition.\nPR:L - The DEV_QUERY ioctl is marked DRM_RENDER_ALLOW, so it needs neither DRM master nor authentication - any unprivileged local user or sandboxed app that can open the render node (standard for GUI/Android/embedded graphics clients) can invoke it.\nUI:N - The attacking process triggers the flaw entirely on its own by issuing a single ioctl; no action by another user or victim process is needed.\nS:U - The out-of-bounds read and the disclosure occur within the kernel and are delivered to the calling process; no other security authority (VM, IOMMU domain) is crossed.\nC:H - With stride > obj_size the kernel source pointer advances by the attacker-chosen stride (up to ~4 GiB) past the static_data_areas array, and copy_to_user hands 16 bytes per element back to userspace; repeating the ioctl with varying strides yields a repeatable read of arbitrary kernel memory at chosen offsets from a known symbol, leaking pointers, keys and other kernel data.\nI:N - Because min_stride equals the object size, only the stride > obj_size case is reachable, so all userspace writes stay inside the caller's own count*stride buffer and no kernel memory is written; the only integrity effect is misplaced/uncleared data in the caller's own buffer.\nA:H - The kernel-side reads walk far outside the static array into unmapped, text or slab memory; with hardened usercopy or KASAN enabled this triggers usercopy_abort()/BUG and a KASAN out-of-bounds report, killing the task or panicking the system, and the fault is trivially repeatable."}]}],"providerMetadata":{"dateUpdated":"2026-08-13T22:42:29.830Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/bbebc39a70f6fc9b02637c8624349e30325873cb"},{"url":"https://git.kernel.org/stable/c/b983a35dad3701399c692d7c6eb57d8b6ffc0929"},{"url":"https://git.kernel.org/stable/c/09beaf4aec05b0525f2153dce693f3eb3166697a"},{"url":"https://git.kernel.org/stable/c/8dc8f3f4c2382fb7d1b1986ba8f33a2466cd3d7a"}],"title":"drm/imagination: Fix user array stride in pvr_set_uobj_array()","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-68262","datePublished":"2026-08-10T12:01:36.582Z","dateReserved":"2026-07-30T09:28:09.378Z","dateUpdated":"2026-08-13T22:42:29.830Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-10 13:20:14","lastModifiedDate":"2026-08-13 23:17:26","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.2}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"68262","Ordinal":"1","Title":"drm/imagination: Fix user array stride in pvr_set_uobj_array()","CVE":"CVE-2026-68262","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"68262","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/imagination: Fix user array stride in pvr_set_uobj_array()\n\npvr_set_uobj_array() copies an array of kernel objects to a userspace\narray whose element size is described by out->stride. When out->stride\nis different from the kernel object size, the slow path advances the\nuserspace pointer by the kernel object size and the kernel pointer by the\nuserspace stride.\n\nThis reverses the intended layout. For larger userspace strides, later\ncopies read from the wrong kernel addresses. For smaller userspace\nstrides, later copies are written at the wrong userspace offsets. The\npadding clear is also done only for the first element instead of the\npadding area for each element.\n\nAdvance the userspace pointer by out->stride and the kernel pointer by\nobj_size, and clear per-element padding while the current userspace\npointer is still available.","Type":"Description","Title":"drm/imagination: Fix user array stride in pvr_set_uobj_array()"}]}}}