Bug 2495950 (CVE-2026-53356)
| Summary: | CVE-2026-53356 kernel: drm/i915/gem: Fix phys BO pread/pwrite with offset | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | rhel-process-autobot, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in the Linux kernel's `drm/i915/gem` component. This vulnerability occurs because the `sg_page()` function incorrectly scales `pread/pwrite` operations for physical Buffer Objects (BO) when a non-zero offset is used. This can lead to incorrect memory access, potentially allowing an attacker to read or write to unintended memory regions. Such access could result in information disclosure or data corruption.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-07-01 14:03:09 UTC
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2026070147-CVE-2026-53356-0d5f@gregkh/T This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:57252 https://access.redhat.com/errata/RHSA-2026:57252 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:57251 https://access.redhat.com/errata/RHSA-2026:57251 |