{"schema_version":"1.7.2","id":"OESA-2026-3452","modified":"2026-08-20T09:58:33Z","published":"2026-08-20T09:58:33Z","upstream":["CVE-2026-63860","CVE-2026-64546"],"summary":"kernel security update","details":"The Linux Kernel, the operating system core itself.\r\n\r\nSecurity Fix(es):\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/core: Prefer NLA_NUL_STRING\n\nThese attributes are evaluated as c-string (passed to strcmp), but\nNLA_STRING doesn&apos;t check for the presence of a \\0 terminator.\n\nEither this needs to switch to nla_strcmp() and needs to adjust printf fmt\nspecifier to not use plain %s, or this needs to use NLA_NUL_STRING.\n\nAs the code has been this way for long time, it seems to me that userspace\ndoes include the terminating nul, even tough its not enforced so far, and\nthus NLA_NUL_STRING use is the simpler solution.(CVE-2026-63860)\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ndrm/edid: fix OOB read in drm_parse_tiled_block()\n\ndrm_parse_tiled_block() casts the DisplayID block to a\nstruct displayid_tiled_block and reads the full fixed layout up to\ntile-&gt;topology_id[7] without checking block-&gt;num_bytes. The DisplayID\niterator only validates the declared payload length, so a crafted EDID\ncan advertise a tiled-display block (tag DATA_BLOCK_TILED_DISPLAY, or\nDATA_BLOCK_2_TILED_DISPLAY_TOPOLOGY for v2.0) with a small num_bytes at\nthe end of a DisplayID extension. The read then runs past the end of the\nexact-sized kmemdup()&apos;d EDID allocation, a heap out-of-bounds read.\n\nReject blocks shorter than the spec&apos;s 22-byte tiled payload before\nreading the fixed struct, as drm_parse_vesa_mso_data() already does.\n\n  BUG: KASAN: slab-out-of-bounds in drm_edid_connector_update\n  Read of size 2 at addr ffff888010077700 by task exploit/147\n   dump_stack_lvl (lib/dump_stack.c:94 ...)\n   print_report (mm/kasan/report.c:378 ...)\n   kasan_report (mm/kasan/report.c:595)\n   drm_edid_connector_update (drivers/gpu/drm/drm_edid.c:7581)\n   bochs_connector_helper_get_modes (drivers/gpu/drm/tiny/bochs.c:574)\n   drm_helper_probe_single_connector_modes (drivers/gpu/drm/drm_probe_helper.c:426)\n   status_store (drivers/gpu/drm/drm_sysfs.c:219)\n   ...\n   vfs_write (fs/read_write.c:595 fs/read_write.c:688)\n   ksys_write (fs/read_write.c:740)(CVE-2026-64546)","affected":[{"package":{"ecosystem":"openEuler:20.03-LTS-SP4","name":"kernel","purl":"pkg:rpm/openEuler/kernel&distro=openEuler-20.03-LTS-SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.19.90-2608.4.0.0386.oe2003sp4"}]}],"ecosystem_specific":{"aarch64":["bpftool-4.19.90-2608.4.0.0386.oe2003sp4.aarch64.rpm","bpftool-debuginfo-4.19.90-2608.4.0.0386.oe2003sp4.aarch64.rpm","kernel-4.19.90-2608.4.0.0386.oe2003sp4.aarch64.rpm","kernel-debuginfo-4.19.90-2608.4.0.0386.oe2003sp4.aarch64.rpm","kernel-debugsource-4.19.90-2608.4.0.0386.oe2003sp4.aarch64.rpm","kernel-devel-4.19.90-2608.4.0.0386.oe2003sp4.aarch64.rpm","kernel-source-4.19.90-2608.4.0.0386.oe2003sp4.aarch64.rpm","kernel-tools-4.19.90-2608.4.0.0386.oe2003sp4.aarch64.rpm","kernel-tools-debuginfo-4.19.90-2608.4.0.0386.oe2003sp4.aarch64.rpm","kernel-tools-devel-4.19.90-2608.4.0.0386.oe2003sp4.aarch64.rpm","perf-4.19.90-2608.4.0.0386.oe2003sp4.aarch64.rpm","perf-debuginfo-4.19.90-2608.4.0.0386.oe2003sp4.aarch64.rpm","python2-perf-4.19.90-2608.4.0.0386.oe2003sp4.aarch64.rpm","python2-perf-debuginfo-4.19.90-2608.4.0.0386.oe2003sp4.aarch64.rpm","python3-perf-4.19.90-2608.4.0.0386.oe2003sp4.aarch64.rpm","python3-perf-debuginfo-4.19.90-2608.4.0.0386.oe2003sp4.aarch64.rpm"],"src":["kernel-4.19.90-2608.4.0.0386.oe2003sp4.src.rpm"],"x86_64":["bpftool-4.19.90-2608.4.0.0386.oe2003sp4.x86_64.rpm","bpftool-debuginfo-4.19.90-2608.4.0.0386.oe2003sp4.x86_64.rpm","kernel-4.19.90-2608.4.0.0386.oe2003sp4.x86_64.rpm","kernel-debuginfo-4.19.90-2608.4.0.0386.oe2003sp4.x86_64.rpm","kernel-debugsource-4.19.90-2608.4.0.0386.oe2003sp4.x86_64.rpm","kernel-devel-4.19.90-2608.4.0.0386.oe2003sp4.x86_64.rpm","kernel-source-4.19.90-2608.4.0.0386.oe2003sp4.x86_64.rpm","kernel-tools-4.19.90-2608.4.0.0386.oe2003sp4.x86_64.rpm","kernel-tools-debuginfo-4.19.90-2608.4.0.0386.oe2003sp4.x86_64.rpm","kernel-tools-devel-4.19.90-2608.4.0.0386.oe2003sp4.x86_64.rpm","perf-4.19.90-2608.4.0.0386.oe2003sp4.x86_64.rpm","perf-debuginfo-4.19.90-2608.4.0.0386.oe2003sp4.x86_64.rpm","python2-perf-4.19.90-2608.4.0.0386.oe2003sp4.x86_64.rpm","python2-perf-debuginfo-4.19.90-2608.4.0.0386.oe2003sp4.x86_64.rpm","python3-perf-4.19.90-2608.4.0.0386.oe2003sp4.x86_64.rpm","python3-perf-debuginfo-4.19.90-2608.4.0.0386.oe2003sp4.x86_64.rpm"]}}],"references":[{"type":"ADVISORY","url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3452"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63860"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64546"}],"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}],"database_specific":{"severity":"Medium"}}
