CVE-2026-68279
drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers
Description
In the Linux kernel, the following vulnerability has been resolved: drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers drm_dp_sideband_parse_remote_dpcd_read() reads num_bytes from the raw message and then unconditionally does: memcpy(bytes, &raw->msg[idx], num_bytes); without checking that idx + num_bytes <= raw->curlen. raw->msg[] is 256 bytes; if a malicious or misbehaving MST hub sets num_bytes larger than the remaining payload, the memcpy reads past the received data into whatever follows in raw->msg[]. drm_dp_sideband_parse_remote_i2c_read_ack() has the same flaw (noted with a /* TODO check */ comment since the code was introduced). Fix both functions by using a single combined check (idx + num_bytes > curlen) before each memcpy. Since num_bytes is u8, it is always >= 0, so this strictly subsumes the simpler idx > curlen form and no separate step is needed. [added missing fixes tag]
INFO
Published Date :
Aug. 10, 2026, 1:20 p.m.
Last Modified :
Aug. 17, 2026, 5:18 a.m.
Remotely Exploit :
No
Source :
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Solution
- Update the Linux kernel to include the fix.
- Verify the patch is applied correctly.
- Reboot the system after the update.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2026-68279.
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2026-68279 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2026-68279
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-68279 vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2026-68279 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Aug. 17, 2026
Action Type Old Value New Value Changed Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': 'ad7f8a1f9ced7f049f9b66d588723f243a7034cd', 'lessThan': '22d9f7fc1aaabaf73d5f30e8b0c9aa814ecd6ed2', 'versionType': 'git'}, {'status': 'affected', 'version': 'ad7f8a1f9ced7f049f9b66d588723f243a7034cd', 'lessThan': '04d953f50d61e542e94a5977822cc53735f8c0ce', 'versionType': 'git'}, {'status': 'affected', 'version': 'ad7f8a1f9ced7f049f9b66d588723f243a7034cd', 'lessThan': '533d9e2bede4aeefdc2a0561d7071cfede95958f', 'versionType': 'git'}, {'status': 'affected', 'version': 'ad7f8a1f9ced7f049f9b66d588723f243a7034cd', 'lessThan': 'e6ef5455b06cb4e5d181aabcd723791587c79f12', 'versionType': 'git'}, {'status': 'affected', 'version': 'ad7f8a1f9ced7f049f9b66d588723f243a7034cd', 'lessThan': '1a8f537f5a1eeac941f262fe73078d6b08ba83c0', 'versionType': 'git'}], 'programFiles': ['drivers/gpu/drm/display/drm_dp_mst_topology.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '3.17'}, {'status': 'unaffected', 'version': '0', 'lessThan': '3.17', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.6.148', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.101', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.42', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.6', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/gpu/drm/display/drm_dp_mst_topology.c'], 'defaultStatus': 'affected'}] [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': 'ad7f8a1f9ced7f049f9b66d588723f243a7034cd', 'lessThan': '22d9f7fc1aaabaf73d5f30e8b0c9aa814ecd6ed2', 'versionType': 'git'}, {'status': 'affected', 'version': 'ad7f8a1f9ced7f049f9b66d588723f243a7034cd', 'lessThan': '04d953f50d61e542e94a5977822cc53735f8c0ce', 'versionType': 'git'}, {'status': 'affected', 'version': 'ad7f8a1f9ced7f049f9b66d588723f243a7034cd', 'lessThan': '533d9e2bede4aeefdc2a0561d7071cfede95958f', 'versionType': 'git'}, {'status': 'affected', 'version': 'ad7f8a1f9ced7f049f9b66d588723f243a7034cd', 'lessThan': 'e6ef5455b06cb4e5d181aabcd723791587c79f12', 'versionType': 'git'}, {'status': 'affected', 'version': 'ad7f8a1f9ced7f049f9b66d588723f243a7034cd', 'lessThan': '1a8f537f5a1eeac941f262fe73078d6b08ba83c0', 'versionType': 'git'}], 'programFiles': ['drivers/gpu/drm/display/drm_dp_mst_topology.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '3.17'}, {'status': 'unaffected', 'version': '0', 'lessThan': '3.17', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.6.148', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.101', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.42', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.6', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/gpu/drm/display/drm_dp_mst_topology.c'], 'defaultStatus': 'affected'}] -
New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Aug. 10, 2026
Action Type Old Value New Value Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': 'ad7f8a1f9ced7f049f9b66d588723f243a7034cd', 'lessThan': '22d9f7fc1aaabaf73d5f30e8b0c9aa814ecd6ed2', 'versionType': 'git'}, {'status': 'affected', 'version': 'ad7f8a1f9ced7f049f9b66d588723f243a7034cd', 'lessThan': '04d953f50d61e542e94a5977822cc53735f8c0ce', 'versionType': 'git'}, {'status': 'affected', 'version': 'ad7f8a1f9ced7f049f9b66d588723f243a7034cd', 'lessThan': '533d9e2bede4aeefdc2a0561d7071cfede95958f', 'versionType': 'git'}, {'status': 'affected', 'version': 'ad7f8a1f9ced7f049f9b66d588723f243a7034cd', 'lessThan': 'e6ef5455b06cb4e5d181aabcd723791587c79f12', 'versionType': 'git'}, {'status': 'affected', 'version': 'ad7f8a1f9ced7f049f9b66d588723f243a7034cd', 'lessThan': '1a8f537f5a1eeac941f262fe73078d6b08ba83c0', 'versionType': 'git'}], 'programFiles': ['drivers/gpu/drm/display/drm_dp_mst_topology.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '3.17'}, {'status': 'unaffected', 'version': '0', 'lessThan': '3.17', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.6.148', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.101', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.42', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.6', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/gpu/drm/display/drm_dp_mst_topology.c'], 'defaultStatus': 'affected'}] Added Description In the Linux kernel, the following vulnerability has been resolved: drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers drm_dp_sideband_parse_remote_dpcd_read() reads num_bytes from the raw message and then unconditionally does: memcpy(bytes, &raw->msg[idx], num_bytes); without checking that idx + num_bytes <= raw->curlen. raw->msg[] is 256 bytes; if a malicious or misbehaving MST hub sets num_bytes larger than the remaining payload, the memcpy reads past the received data into whatever follows in raw->msg[]. drm_dp_sideband_parse_remote_i2c_read_ack() has the same flaw (noted with a /* TODO check */ comment since the code was introduced). Fix both functions by using a single combined check (idx + num_bytes > curlen) before each memcpy. Since num_bytes is u8, it is always >= 0, so this strictly subsumes the simpler idx > curlen form and no separate step is needed. [added missing fixes tag] Added Reference https://git.kernel.org/stable/c/04d953f50d61e542e94a5977822cc53735f8c0ce Added Reference https://git.kernel.org/stable/c/1a8f537f5a1eeac941f262fe73078d6b08ba83c0 Added Reference https://git.kernel.org/stable/c/22d9f7fc1aaabaf73d5f30e8b0c9aa814ecd6ed2 Added Reference https://git.kernel.org/stable/c/533d9e2bede4aeefdc2a0561d7071cfede95958f Added Reference https://git.kernel.org/stable/c/e6ef5455b06cb4e5d181aabcd723791587c79f12