CVE-2026-80749
In the Linux kernel, the following vulnerability has been resolved:
drm/connector/hdmi: Fix out of bounds memory read
A helper function was copying a given audio infoframe into the connector's copy but using the size of the destination (a generic target, sized to accept many different data blocks) not the source (a very specific type of data block). Thus, it was copying 60 bytes of data from a 28 byte allocation.
Fix that by using the source size instead, together with a build bug on the source size actually being smaller than the destination.
I hit this running KUnit tests under KASAN (while debugging something else entirely). In the real world, it seems unlikely to cause an actual problem.
Leer descripción completaMostrar menos
It is a read not a write so it can't corrupt any memory. However, it could potentially fall off the end of a page and cause an accvio bug.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
- Puntuación base: 7.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.17%
- Percentil entre todas las CVEs puntuadas: 5
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1068Exploitation for Privilege Escalationprivilege escalation75 % - Impacto principal
T1005Data from Local Systemcollection65 %
Vulnerabilidad local (AV:L, PR:L) en kernel Linux; lectura fuera de límites (60 bytes vs 28 asignados) sin corrupción de memoria, pero acceso a datos sensibles potencial en estructura de infoframe HDMI.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-80749",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.1,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "f378b77227bc4732922c57f92be89438bb1018a1",
"lessThan": "d9f7454c185c0c7f0973e11d62ad6c06862c324c",
"versionType": "git"
},
{
"status": "affected",
"version": "f378b77227bc4732922c57f92be89438bb1018a1",
"lessThan": "e5b527804a1ea4f70e139179d3062cf5de8c06ab",
"versionType": "git"
},
{
"status": "affected",
"version": "f378b77227bc4732922c57f92be89438bb1018a1",
"lessThan": "f72bb95732bc5ca87b50c52c8f087ba501950809",
"versionType": "git"
},
{
"status": "affected",
"version": "f378b77227bc4732922c57f92be89438bb1018a1",
"lessThan": "9ecf8ba763d0ffe0673538eb4bf7806f20455d19",
"versionType": "git"
}
],
"programFiles": [
"drivers/gpu/drm/display/drm_hdmi_state_helper.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.11"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.11",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/gpu/drm/display/drm_hdmi_state_helper.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-03T13:06:14.520",
"references": [
{
"url": "https://git.kernel.org/stable/c/9ecf8ba763d0ffe0673538eb4bf7806f20455d19",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/d9f7454c185c0c7f0973e11d62ad6c06862c324c",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/e5b527804a1ea4f70e139179d3062cf5de8c06ab",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f72bb95732bc5ca87b50c52c8f087ba501950809",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/connector/hdmi: Fix out of bounds memory read\n\nA helper function was copying a given audio infoframe into the\nconnector's copy but using the size of the destination (a generic\ntarget, sized to accept many different data blocks) not the source (a\nvery specific type of data block). Thus, it was copying 60 bytes of\ndata from a 28 byte allocation.\n\nFix that by using the source size instead, together with a build bug\non the source size actually being smaller than the destination.\n\nI hit this running KUnit tests under KASAN (while debugging something\nelse entirely). In the real world, it seems unlikely to cause an\nactual problem. It is a read not a write so it can't corrupt any\nmemory. However, it could potentially fall off the end of a page and\ncause an accvio bug."
}
],
"lastModified": "2026-09-04T05:17:14.877",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}