CVE-2026-53138 Details
Description
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Bound VBIOS record-chain walk loops [Why & How] All record-chain walk loops in bios_parser.c and bios_parser2.c use for(;;) and only terminate on a 0xFF record_type sentinel or zero record_size. A malformed VBIOS image missing the terminator record causes unbounded iteration at probe time, potentially hundreds of thousands of iterations with record_size=1. In the final iterations near the BIOS image boundary, struct casts beyond the 2-byte header validated by GET_IMAGE can also read out of bounds. Cap all 14 record-chain walk loops to BIOS_MAX_NUM_RECORD (256) iterations. The atombios.h defines up to 22 distinct record types and atomfirmware.h has 13. Assuming an average of less than 10 records per type (which is reasonable since most are connector- based) 256 is a generous upper bound. (cherry picked from commit 95700a3d660287ed657d6892f7be9ffc0e294a93)
A vulnerability in the Linux kernel's handling of VBIOS record chains can lead to unbounded iteration and potential out-of-bounds memory access. This issue occurs in the AMD display driver, specifically within the VBIOS parsing functions. The vulnerability affects all versions of the Linux kernel prior to the patch included in this commit. The problem arises because the record-chain walk loops do not have a proper termination condition, allowing a malformed VBIOS image to cause excessive iterations. In the later stages of this iteration, the parsing can read beyond the intended memory boundaries, creating a risk of memory corruption or other unintended behavior.
Users can update to the latest version of the Linux kernel, where this vulnerability has been addressed. The patch is included in the official Linux stable releases.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/04e271a952b8863bbafc99bd51aca4c32bff0e0d | kernel.org | Patch |
| https://git.kernel.org/stable/c/0e56f460bddb397fa9a8e6faf7ae7eaa86953eb1 | kernel.org | Patch |
| https://git.kernel.org/stable/c/2645e3caf7e013189da9c6ff621d006cca5a538b | kernel.org | Patch |
| https://git.kernel.org/stable/c/499c6b43a79dd684bddbd18fe8b2235aa2764db4 | kernel.org | Patch |
| https://git.kernel.org/stable/c/6173cfea2f916e01c4f98e29cd654384a05e32a3 | kernel.org | Patch |
| https://git.kernel.org/stable/c/6723188c42ca3b34a9fce634d7a0ecc9ccd5cd56 | kernel.org | Patch |
| https://git.kernel.org/stable/c/e94f5323c41f32a74160378c3b19850d1f203ad5 | kernel.org | Patch |
| https://git.kernel.org/stable/c/ff287df16a1a58aca78b08d1f3ee09fc44da0351 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 4.15, < 5.10.260 >= 5.11, < 5.15.211 >= 5.16, < 6.1.177 >= 6.2, < 6.6.144 >= 6.7, < 6.12.94 >= 6.13, < 6.18.36 >= 6.19, < 7.0.13 7.1 rc1 7.1 rc2 7.1 rc3 7.1 rc4 7.1 rc5 7.1 rc6 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 7, 2026 | Initial Analysis | [email protected] |
| Jul 4, 2026 | CVE Modified | kernel.org |
| Jun 25, 2026 | New CVE Received | kernel.org |