---
id: CVE-2024-26660
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  drm/amd/display: Implement bounds check for stream encoder creation in DCN301

  'stream_enc_regs' array is an array of dcn10_stream_enc_registers
  structures
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  drm/amd/display: Implement bounds check for stream encoder creation in DCN301

  'stream_enc_regs' array is an array of dcn10_stream_enc_registers
  structures. The array i…
severity: high
cvss: 7
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-125
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 5.11, < 5.15.149'
  - 'linux_kernel >= 5.16, < 6.1.78'
  - 'linux_kernel >= 6.2, < 6.6.17'
  - 'linux_kernel >= 6.7, < 6.7.5'
  - linux_kernel = 6.8
patched:
  - linux_kernel 6.7.5
published: '2024-04-02'
updated: '2026-08-04'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-26660'
references:
  - url: 'https://git.kernel.org/stable/c/42442f74314d41ddc68227047036fa3e78940054'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/58fca355ad37dcb5f785d9095db5f748b79c5dc2'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/a938eab9586eea31cfd129a507f552efae14d738'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/cd9bd10c59e3c1446680514fd3097c5b00d3712d'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/efdd665ce1a1634b8c1dad5e7f6baaef3e131d0a'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/42442f74314d41ddc68227047036fa3e78940054'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/58fca355ad37dcb5f785d9095db5f748b79c5dc2'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/a938eab9586eea31cfd129a507f552efae14d738'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/cd9bd10c59e3c1446680514fd3097c5b00d3712d'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/efdd665ce1a1634b8c1dad5e7f6baaef3e131d0a'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00264
epssPercentile: 0.16285
ingestedAt: '2026-08-05T10:46:47.765Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

drm/amd/display: Implement bounds check for stream encoder creation in DCN301

'stream_enc_regs' array is an array of dcn10_stream_enc_registers
structures. The array is initialized with four elements, corresponding
to the four calls to stream_enc_regs() in the array initializer. This
means that valid indices for this array are 0, 1, 2, and 3.

The error message 'stream_enc_regs' 4 <= 5 below, is indicating that
there is an attempt to access this array with an index of 5, which is
out of bounds. This could lead to undefined behavior

Here, eng_id is used as an index to access the stream_enc_regs array. If
eng_id is 5, this would result in an out-of-bounds access on the
stream_enc_regs array.

Thus fixing Buffer overflow error in dcn301_stream_encoder_create
reported by Smatch:
drivers/gpu/drm/amd/amdgpu/../display/dc/resource/dcn301/dcn301_resource.c:1011 dcn301_stream_encoder_create() error: buffer overflow 'stream_enc_regs' 4 <= 5

## Affected

- `linux_kernel >= 5.11, < 5.15.149`
- `linux_kernel >= 5.16, < 6.1.78`
- `linux_kernel >= 6.2, < 6.6.17`
- `linux_kernel >= 6.7, < 6.7.5`
- `linux_kernel = 6.8`

## Remediation

Upgrade past the affected range:

- `linux_kernel 6.7.5`
