---
id: CVE-2026-93234
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  drm/gud: validate TV mode names before creating enum property

  The GUD protocol returns TV mode names as fixed-size
  GUD_CONNECTOR_TV_MODE_NAME_LEN entries and requires …
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  drm/gud: validate TV mode names before creating enum property

  The GUD protocol returns TV mode names as fixed-size
  GUD_CONNECTOR_TV_MODE_NAME_LEN entries and requires …
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 40e1a70b4aedf2859a1829991b48ef0ebe650bf2 <
    676f1fb3632bbc9ce83be7938e93fe6bfc9510fd
  - >-
    Linux >= 40e1a70b4aedf2859a1829991b48ef0ebe650bf2 <
    06fcaf21c18ac88f57fee3803554f48c6026b95f
  - >-
    Linux >= 40e1a70b4aedf2859a1829991b48ef0ebe650bf2 <
    082e378886547b5b1c4075ed307f7c68547868dc
  - >-
    Linux >= 40e1a70b4aedf2859a1829991b48ef0ebe650bf2 <
    70cffc31a380b3eae45027101647aa94c242aa0e
  - >-
    Linux >= 40e1a70b4aedf2859a1829991b48ef0ebe650bf2 <
    72a95df6bbc7d20c7af1e39d86b3e910cccd01ad
  - >-
    Linux >= 40e1a70b4aedf2859a1829991b48ef0ebe650bf2 <
    eab46d9629807db1b5647d17227e16110a18227f
  - >-
    Linux >= 40e1a70b4aedf2859a1829991b48ef0ebe650bf2 <
    da1ea35fea67ad841f4ada28dd61b41be65e5437
  - Linux 5.13
published: '2026-09-24'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T16:17:19.007'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-93234'
references:
  - url: 'https://git.kernel.org/stable/c/06fcaf21c18ac88f57fee3803554f48c6026b95f'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/082e378886547b5b1c4075ed307f7c68547868dc'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/676f1fb3632bbc9ce83be7938e93fe6bfc9510fd'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/70cffc31a380b3eae45027101647aa94c242aa0e'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/72a95df6bbc7d20c7af1e39d86b3e910cccd01ad'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/da1ea35fea67ad841f4ada28dd61b41be65e5437'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/eab46d9629807db1b5647d17227e16110a18227f'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-24T15:45:56.659Z'
epss: 0.00205
epssPercentile: 0.09381
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

drm/gud: validate TV mode names before creating enum property

The GUD protocol returns TV mode names as fixed-size
GUD_CONNECTOR_TV_MODE_NAME_LEN entries and requires each name to be
NUL-terminated.

gud_connector_add_tv_mode() currently passes each fixed-size entry
directly to drm_mode_create_tv_properties_legacy(), which eventually
reaches drm_property_add_enum() and strlen(). If a device returns an
entry without a terminating NUL byte, strlen() reads past the end of
the slot and can run beyond the allocated buffer, triggering an
out-of-bounds read.

Validate that each returned TV mode name contains a NUL terminator
within its fixed-size slot before passing it to the DRM property code.
If a malformed entry is found, reject the device response with -EIO.

This fixes the out-of-bounds read without changing the handling of
valid devices, and avoids silently truncating malformed protocol data.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
