« Volver al listado

CVE-2026-68255

Estado: RecibidaAlta (7.7)—

In the Linux kernel, the following vulnerability has been resolved:

drm/virtio: bound EDID block reads to the response buffer

virtio_get_edid_block() validates the read offset only against the device-supplied resp->size field, never against the fixed-size resp->edid array. The EDID block index is driven by the device-supplied extension count, so a malicious virtio-gpu backend can advertise a large size together with a high block count and read far past the array into adjacent kernel memory, which is then surfaced in the parsed EDID (an out-of-bounds read / info leak).

Also reject any read whose end exceeds the size of the edid array. Conforming EDID responses stay within the array and are unaffected.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad de lectura fuera de límites en el kernel Linux (AV:L, PR:N, UI:N) que permite a un atacante local acceder a memoria adyacente del kernel, causando fuga de información (info leak); potencial DoS por acceso a estructuras críticas.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-68255",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.7,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 2.5
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "b4b01b4995fb15b55a2d067eb405917f5ab32709",
              "lessThan": "65ce911f341ad8ff0c08922eff5bb6db75666eb0",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b4b01b4995fb15b55a2d067eb405917f5ab32709",
              "lessThan": "64bedd2758eccbc74d39f7006a7ec16fa39dc901",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b4b01b4995fb15b55a2d067eb405917f5ab32709",
              "lessThan": "3f506a85a905b080cadc029a1651a310479090a6",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b4b01b4995fb15b55a2d067eb405917f5ab32709",
              "lessThan": "9fc2a017c5d597937e0c28b9a9669844aa796c42",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b4b01b4995fb15b55a2d067eb405917f5ab32709",
              "lessThan": "2757e6e803092cf0aeaf4b735e16b5d3bdc705c5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b4b01b4995fb15b55a2d067eb405917f5ab32709",
              "lessThan": "35be0e2c6862abcd5e5f5445261f1fd910d4a9b4",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b4b01b4995fb15b55a2d067eb405917f5ab32709",
              "lessThan": "375c1934ef0196d3b6d3a1eae3232bef8dae7bf7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b4b01b4995fb15b55a2d067eb405917f5ab32709",
              "lessThan": "4e1a53892ba7f8a3e1da6bfc53c83ae7c812dccd",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/gpu/drm/virtio/virtgpu_vq.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.0"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.266",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.217",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.183",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.148",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.101",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.42",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/gpu/drm/virtio/virtgpu_vq.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-10T13:20:14.113",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/2757e6e803092cf0aeaf4b735e16b5d3bdc705c5",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/35be0e2c6862abcd5e5f5445261f1fd910d4a9b4",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/375c1934ef0196d3b6d3a1eae3232bef8dae7bf7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/3f506a85a905b080cadc029a1651a310479090a6",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/4e1a53892ba7f8a3e1da6bfc53c83ae7c812dccd",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/64bedd2758eccbc74d39f7006a7ec16fa39dc901",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/65ce911f341ad8ff0c08922eff5bb6db75666eb0",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9fc2a017c5d597937e0c28b9a9669844aa796c42",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/virtio: bound EDID block reads to the response buffer\n\nvirtio_get_edid_block() validates the read offset only against the\ndevice-supplied resp->size field, never against the fixed-size resp->edid\narray. The EDID block index is driven by the device-supplied extension\ncount, so a malicious virtio-gpu backend can advertise a large size\ntogether with a high block count and read far past the array into adjacent\nkernel memory, which is then surfaced in the parsed EDID (an out-of-bounds\nread / info leak).\n\nAlso reject any read whose end exceeds the size of the edid array.\nConforming EDID responses stay within the array and are unaffected."
    }
  ],
  "lastModified": "2026-08-23T13:16:35.730",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}