目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2026-53330— Linux kernel 安全漏洞

AI Predicted 4.4 Difficulty: Moderate EPSS 0.17% · P6

Possible ATT&CK Techniques 1AI

T1200 · Hardware Additions

Affected Version Matrix 8

ベンダープロダクトVersion Rangeステータス
LinuxLinux8e5100a575433cc185a2e224280fbd873b6692dd< 454d3b3d499c18373f8960d31aea48338a3ca9e0affected
8e5100a575433cc185a2e224280fbd873b6692dd< dc1490927d79fe9621e29f4a4f5d7b5ccb6aea3eaffected
8e5100a575433cc185a2e224280fbd873b6692dd< e8b4d37eba05141ee01794fc6b7f2da808cee83baffected
5.6affected
< 5.6unaffected
6.18.36≤ 6.18.*unaffected
7.0.13≤ 7.0.*unaffected
7.1≤ *unaffected
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2026-53330の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
drm/amd/display: Fix out-of-bounds read in dp_get_eq_aux_rd_interval()
ソース: NVD (National Vulnerability Database)
脆弱性説明
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix out-of-bounds read in dp_get_eq_aux_rd_interval() [Why & How] The aux_rd_interval array in struct dc_lttpr_caps is declared with MAX_REPEATER_CNT - 1 (7) elements, indexed 0..6. However, the offset parameter passed to dp_get_eq_aux_rd_interval() can be as large as MAX_REPEATER_CNT (8) when a sink reports 8 LTTPR repeaters via DPCD. This leads to an out-of-bounds read of aux_rd_interval[7] when offset is 8. Fix this by growing aux_rd_interval to MAX_REPEATER_CNT elements to accommodate the full range of valid repeater counts defined by the DP spec. (cherry picked from commit a55a458a8df37a65ffda5cf721d554a8f74f6b04)
ソース: NVD (National Vulnerability Database)
CVSS情報
N/A
ソース: NVD (National Vulnerability Database)
脆弱性タイプ
N/A
ソース: NVD (National Vulnerability Database)
脆弱性タイトル
Linux kernel 安全漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Linux kernel是美国Linux基金会开源的一款操作系统内核。 Linux kernel存在安全漏洞,该漏洞源于dp_get_eq_aux_rd_interval()函数中存在越界读取问题,当sink通过DPCD报告8个LTTPR repeater时,offset参数可达MAX_REPEATER_CNT (8),导致对aux_rd_interval[7]的越界读取。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
LinuxLinux 8e5100a575433cc185a2e224280fbd873b6692dd ~ 454d3b3d499c18373f8960d31aea48338a3ca9e0 -
LinuxLinux 5.6 -

II. CVE-2026-53330の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2026-53330のインテリジェンス情報

登录查看更多情报信息。

CVE-2026-53330 补丁与修复 (3)

Same Patch Batch · Linux · 2026-07-01 · 31 CVEs total

CVE-2026-533559.8 CRITICALnet: rds: clear i_sends on setup unwind
CVE-2026-533548.8 HIGHarm64: errata: Mitigate TLBI errata on various Arm CPUs
CVE-2026-533567.8 HIGHdrm/i915/gem: Fix phys BO pread/pwrite with offset
CVE-2026-533417.8 HIGHfhandle: fix UAF due to unlocked ->mnt_ns read in may_decode_fh()
CVE-2026-533297.0 HIGHdrm/amd/display: Use krealloc_array() in dal_vector_reserve()
CVE-2026-53342arm64: mm: call pagetable dtor when freeing hot-removed page tables
CVE-2026-53353hsr: Remove WARN_ONCE() in hsr_addr_is_self().
CVE-2026-53352signal: clear JOBCTL_PENDING_MASK for caller in zap_other_threads()
CVE-2026-53351riscv/ptrace: Use USER_REGSET_NOTE_TYPE for REGSET_CFI
CVE-2026-53350ASoC: wm_adsp: Fix NULL dereference when removing firmware controls
CVE-2026-53348ASoC: SDCA: fix NULL pointer dereference in sdca_dev_unregister_functions
CVE-2026-53349netfilter: nf_conntrack: destroy stale expectfn expectations on unregister
CVE-2026-53346rust: arm64: set uwtable llvm module flag for CONFIG_UNWIND_TABLES
CVE-2026-53347drm/virtio: Fix driver removal with disabled KMS
CVE-2026-53344pinctrl: mcp23s08: Initialize mcp->dev and mcp->addr before regmap init
CVE-2026-53345KVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying
CVE-2026-53343ARM: 9475/1: entry: use byte load for KASAN VMAP stack shadow
CVE-2026-53327debugobjects: Do not fill_pool() if pi_blocked_on
CVE-2026-53340i2c: imx: fix clock and pinctrl state inconsistency in runtime PM
CVE-2026-53339i2c: qcom-cci: Fix NULL pointer dereference in cci_remove()

Showing 20 of 31 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2026-53330へのコメント

まだコメントはありません


コメントを残す