Out-of-Bounds Array Access in Linux Kernel UCSI DisplayPort Driver
CVE-2026-90025
What is CVE-2026-90025?
A vulnerability exists in the UCSI DisplayPort driver of the Linux kernel, where improper validation of the GET_CURRENT_CAM response can lead to an out-of-bounds access in the port altmode array. If the response indicates an index above the maximum defined size (UCSI_MAX_ALTMODES), it can cause the kernel to crash, undermining system stability. Proper checks have been introduced to ensure the response is verified against the array bounds before accessing it, enhancing the driver's robustness against such issues.
Affected Version(s)
Linux af8622f6a585d8d82b11cd7987e082861fd0edd3 < 8fde7e4a366184e9a6aa95541e52933a73c00a74
Linux af8622f6a585d8d82b11cd7987e082861fd0edd3 < 83f1abd62cc134700ba92e1e2dc650a49a185497
Linux af8622f6a585d8d82b11cd7987e082861fd0edd3 < 1ffed96ef986e2cdf986aa4a4506a5e6dcdf4456