Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-68235

Published Aug 10, 2026 EPSS 0.20% (10th pctl)

Overview

CVE-2026-68235 is a known-severity vulnerability. It was published on August 10, 2026.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

drm/amd/display: dce100: skip non-DP stream encoders for DP MST

On DCE8-class ASICs (e.g. Bonaire), the resource pool contains digital

DIG stream encoders plus one analog DAC encoder. When assigning a stream

encoder for a second DisplayPort MST stream, if the preferred digital

encoder is already acquired, dce100_find_first_free_match_stream_enc_for_link()

falls back to the first free pool entry. That entry may be the analog

encoder, whose funcs table lacks DP hooks such as dp_set_stream_attribute.

The subsequent atomic commit then dereferences NULL function pointers in

link_set_dpms_on() and crashes.

Skip encoders without dp_set_stream_attribute when the stream uses a DP

signal (including MST). Use dc_is_dp_signal(stream->signal) for the MST

fallback path instead of checking only the link connector signal.

Tested on:

- GPU: AMD Radeon R7 260X (Bonaire / DCE8)

- Board: Supermicro C9X299-PG300

- Setup: DP MST daisy c

Remediation

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Frequently Asked Questions

What is CVE-2026-68235?

CVE-2026-68235 is a known-severity vulnerability. It was published on August 10, 2026.

How severe is CVE-2026-68235?

CVSS score information is not yet available for this vulnerability. Check back as the CVE record is updated by NVD analysts.

How do I fix or remediate CVE-2026-68235?

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-68235?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-68235 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.