HomeDefectsLIN1022-34233
Fixed

LIN1022-34233 : Security Advisory - linux - CVE-2026-97621

Created: Sep 25, 2026    Updated: Sep 29, 2026
Resolved Date: Sep 26, 2026
Found In Version: 10.22.33.2
Fix Version: 10.22.33.11
Severity: Standard
Applicable for: Wind River Linux LTS 22
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:  drm/rockchip: analogix_dp: fix unchecked bound endpoint name length  rockchip_dp_drm_encoder_enable() uses sprintf() to format a device tree path into a 32-byte stack buffer. Device tree paths are not limited to this size, so a sufficiently long path can overflow the buffer.  Use snprintf() with the destination size to truncate the generated name and keep the writes within bounds.
Data source: kernel.org (416baaa9-dc9f-4396-8d5f-8c081fb06d67)

CVEs