Bug 2513278 (CVE-2026-68262)
| Summary: | CVE-2026-68262 kernel: drm/imagination: Fix user array stride in pvr_set_uobj_array() | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | rhel-process-autobot, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in the Linux kernel. The `drm/imagination` component's `pvr_set_uobj_array()` function mishandles the user array stride during copies of kernel objects to a userspace array. This error causes incorrect memory access, leading to memory corruption where data is written to unintended locations, or information disclosure where sensitive kernel data is read from incorrect addresses. A local attacker could potentially leverage this to gain elevated privileges or cause a system crash (Denial of Service).
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-08-10 12:28:34 UTC
|