Skip to content
VulniPulse
Advisory severityHigh7.3Vendor: MediumRed Hat Linux

High [CVE-2026-68278] fix buffer overflows in sideband chunk accumulation

This high-severity Red Hat Linux advisory covers CVE-2026-68278 affecting Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9.

Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.

CVE-2026-68278 Source published Source updated

VulniPulse record published Record updated

Affected products & platforms
Red Hat LinuxLinux Kernel
Open source advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

In the Linux kernel, the following vulnerability has been resolved: drm/dp/mst: fix buffer overflows in sideband chunk accumulation drm_dp_sideband_append_payload() has three related bugs when processing device-provided sideband reply data: 1. Zero-length curchunk_len underflow: msg_len is a 6-bit field taken directly from the DP sideband header.

If a device sends msg_len=0, curchunk_len is set to zero. The condition (curchunk_idx >= curchunk_len) is immediately true, and curchunk_len-1 wraps to 255 (u8 underflow). drm_dp_msg_data_crc4() reads 255 bytes from chunk[48], then memcpy() writes 255 bytes into msg[], both far out of bounds.

2. chunk[48] overflow: curchunk_len can reach 63 (6-bit field). chunk[] is only 48 bytes. Multi-iteration payload assembly appends 16-byte blocks until curchunk_idx reaches curchunk_len, writing up to 15 bytes past the end of chunk[] into msg[].

3. msg[256] overflow: each chunk contributes (curchunk_len-1) bytes to msg[]. No check ensures curlen + (curchunk_len-1) stays within msg[256], so the memcpy can spill into adjacent struct fields.

All three are reachable from any DP MST device that can forge sideband reply messages on a physical connection. A flaw was found in the Linux kernel's DisplayPort (DP) Multi-Stream Transport (MST) subsystem.

Affected versions

No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.

Official advisory · high-confidence parse· fetched 26 minutes ago·verify at source

Fixed versions

No fixed release is recorded yet. That does not prove no patch exists — confirm against the vendor advisory.

Official advisory · high-confidence parse· fetched 26 minutes ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • Prevent the 'drm_dp_mst' kernel module from loading to mitigate this vulnerability. This will disable DisplayPort Multi-Stream Transport functionality, which may affect multi-monitor setups using DisplayPort. To blacklist the module, create a file named `/etc/modprobe.d/blacklist-drm_dp_mst.conf` with the following content: ``` blacklist drm_dp_mst ``` Then, regenerate the initramfs and reboot the system for the changes to take effect: ```bash drancut --force --kver $(uname -r) reboot ``` A system reboot is required for the module to be unloaded and the mitigation to be active. This may impact display functionality if DP MST is in use.

Official advisory · high-confidence parse· fetched 26 minutes ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.