Bug 2545178 (CVE-2026-93522) - CVE-2026-93522 glamor: size tmp_bits buffer for source coordinate range in upload_boxes
Summary: CVE-2026-93522 glamor: size tmp_bits buffer for source coordinate range in u...
Keywords:
Status: NEW
Alias: CVE-2026-93522
Deadline: 2026-10-07
Product: Security Response
Classification: Other
Component: vulnerability-draft
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-10-02 13:04 UTC by OSIDB Bzimport
Modified: 2026-10-08 09:34 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-10-02 13:04:41 UTC
glamor_upload_boxes() allocates the tmp_bits buffer (used for 24-bit to
32-bit depth conversion) based on the destination pixmap height, but
indexes it using source coordinates (y1 - dy_dst + dy_src). When the
source is taller than the destination, the source-relative offset
exceeds the destination height, causing writes past the buffer end.

Size the buffer to account for the source coordinate mapping:
byte_stride * (pixmap->drawable.height - dy_dst + dy_src). This
ensures the buffer covers the full range of source rows that will be
accessed during the upload.

This vulnerability was discovered by:
  Anonymous working with TrendAI Zero Day Initiative

ZDI-CAN-32361


Note You need to log in before you can comment on or make changes to this bug.