Linux Kernel Hyper-V DRM: Prevent VMBus Packet Size Over-read
CVE-2026-64527 Published on July 25, 2026
drm/hyperv: validate VMBus packet size in receive callback
In the Linux kernel, the following vulnerability has been resolved:
drm/hyperv: validate VMBus packet size in receive callback
hyperv_receive_sub() reads msg->vid_hdr.type and dispatches into one
of four message-type branches without knowing how many bytes the host
wrote into hv->recv_buf. The completion path then runs
memcpy(hv->init_buf, msg, VMBUS_MAX_PACKET_SIZE), so the consumer that
wakes on wait_for_completion_timeout() can read up to 16 KiB of
residue from a prior message as if it were the response payload.
Pass bytes_recvd into hyperv_receive_sub() and reject any packet that
does not cover the pipe + synthvid header. A single switch on
msg->vid_hdr.type then computes the type-specific payload size: the
three completion-driving types (SYNTHVID_VERSION_RESPONSE,
SYNTHVID_RESOLUTION_RESPONSE, SYNTHVID_VRAM_LOCATION_ACK) fall through
to a shared exit that requires that size before memcpy/complete, while
SYNTHVID_FEATURE_CHANGE validates its own payload and returns before
reading is_dirt_needed. Unknown types are dropped.
SYNTHVID_RESOLUTION_RESPONSE is variable length: the host fills
resolution_count entries, not the full SYNTHVID_MAX_RESOLUTION_COUNT
array. Validate the fixed prefix first so resolution_count can be
read, bound it against the array, then require only the count-sized
array, so the shorter responses the host actually sends are accepted.
Only run the sub-handler when vmbus_recvpacket() returned success. The
memcpy length is bytes_recvd, which is bounded by VMBUS_MAX_PACKET_SIZE
only on a successful receive; on -ENOBUFS vmbus_recvpacket() instead
reports the required length, which can exceed hv->recv_buf, so copying
bytes_recvd would read and write past the 16 KiB buffers. Gating on the
success return keeps the copy bounded. The nonzero-return path is itself
a malformed-message case and is now logged rather than silently skipped;
channel recovery is not attempted.
Rejected packets are reported via drm_err_ratelimited() rather than
silently dropped, matching the CoCo-hardened pattern in
hv_kvp_onchannelcallback().
Products Associated with CVE-2026-64527
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 76c56a5affeba1e163b66b9d8cc192e6154466f0 and below 57d5d697642e05d5dd2d40660817765943dd709f is affected.
- Version 76c56a5affeba1e163b66b9d8cc192e6154466f0 and below f5251226551bfec98c4705641b6f94ff1f238d91 is affected.
- Version 76c56a5affeba1e163b66b9d8cc192e6154466f0 and below 049a6b474823049fe60212f25f26e4b30f44ee8f is affected.
- Version 76c56a5affeba1e163b66b9d8cc192e6154466f0 and below 588c84b461393ff1998ac7b97b04f953f642e0df is affected.
- Version 76c56a5affeba1e163b66b9d8cc192e6154466f0 and below 164dc7bf17609340233c6bf4f66bb7c7008a0511 is affected.
- Version 76c56a5affeba1e163b66b9d8cc192e6154466f0 and below c8974d96b6a5496f33dc69a3ce28a7bf5078def4 is affected.
- Version 76c56a5affeba1e163b66b9d8cc192e6154466f0 and below 7f87763f47a3c22fb50265a00619ef10f2394b18 is affected.
- Version 5.14 is affected.
- Before 5.14 is unaffected.
- Version 5.15.210, <= 5.15.* is unaffected.
- Version 6.1.176, <= 6.1.* is unaffected.
- Version 6.6.143, <= 6.6.* is unaffected.
- Version 6.12.93, <= 6.12.* is unaffected.
- Version 6.18.35, <= 6.18.* is unaffected.
- Version 7.0.12, <= 7.0.* is unaffected.
- Version 7.1, <= * is unaffected.