---
id: CVE-2026-97621
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  drm/rockchip: analogix_dp: fix unchecked bound endpoint name length

  rockchip_dp_drm_encoder_enable() uses sprintf() to format a device tree
  path into a 32-byte stack b…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  drm/rockchip: analogix_dp: fix unchecked bound endpoint name length

  rockchip_dp_drm_encoder_enable() uses sprintf() to format a device tree
  path into a 32-byte stack b…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 729f8eefdcadaff98606931e691910f17d8d59d6 <
    49f5268f43a791dd0d9ff554cce25a3685c7250b
  - >-
    Linux >= 729f8eefdcadaff98606931e691910f17d8d59d6 <
    2fcd112caa4ebc64fdcb509f0b26d8daa3fac950
  - >-
    Linux >= 729f8eefdcadaff98606931e691910f17d8d59d6 <
    bc69439d983cc491cc86e01fafc1deb94e1bb85e
  - Linux 6.16
published: '2026-09-25'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T11:17:16.360'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-97621'
references:
  - url: 'https://git.kernel.org/stable/c/2fcd112caa4ebc64fdcb509f0b26d8daa3fac950'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/49f5268f43a791dd0d9ff554cce25a3685c7250b'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/bc69439d983cc491cc86e01fafc1deb94e1bb85e'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-25T11:06:38.896Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

drm/rockchip: analogix_dp: fix unchecked bound endpoint name length

rockchip_dp_drm_encoder_enable() uses sprintf() to format a device tree
path into a 32-byte stack buffer. Device tree paths are not limited to
this size, so a sufficiently long path can overflow the buffer.

Use snprintf() with the destination size to truncate the generated name
and keep the writes within bounds.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
