7.8
CVE-2026-89819
- EPSS 0.16%
- Veröffentlicht 16.09.2026 10:30:51
- Zuletzt bearbeitet 16.09.2026 15:18:11
- Erkennungen
drm/amd/display: validate plane degamma LUT size for private color prop
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: validate plane degamma LUT size for private color prop Unlike the CRTC degamma path, which is guarded by amdgpu_dm_verify_lut_sizes(), the per-plane degamma LUT size was never validated before use. __set_dm_plane_degamma() passed the user-supplied size straight into __is_lut_linear() and, for a non-linear LUT, into __set_input_tf() -> __drm_lut_to_dc_gamma(), the latter always iterating MAX_COLOR_LUT_ENTRIES entries regardless of the actual LUT size. A malformed AMD_PLANE_DEGAMMA_LUT blob (e.g. a single entry) could thus trigger a divide-by-zero in __is_lut_linear() or an out-of-bounds read in __drm_lut_to_dc_gamma(). Reject any plane degamma LUT whose size does not match MAX_COLOR_LUT_ENTRIES, mirroring the invariant the code already asserts a few lines below (and which the CRTC path enforces). The AMD_PLANE_DEGAMMA_LUT property is only exposed on builds with AMD_PRIVATE_COLOR defined.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
980f8710075acaeb226a94cde6dda8ffad30123c
Version <
f6f04d8ae5725bcc893bdc62e3467efd97255c5b
Status
affected
Version
980f8710075acaeb226a94cde6dda8ffad30123c
Version <
0b2615b8b54f58bbdf986dffb38cbc35214a5cc5
Status
affected
Version
980f8710075acaeb226a94cde6dda8ffad30123c
Version <
b10cc09b329245c6d95f8fa3e7f068575e3e0e9f
Status
affected
Version
980f8710075acaeb226a94cde6dda8ffad30123c
Version <
e4c3ab59021e7c146a84b6671f0d530972bd58b4
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
6.8
Status
affected
Version
0
Version <
6.8
Status
unaffected
Version <=
6.12.*
Version
6.12.110
Status
unaffected
Version <=
6.18.*
Version
6.18.51
Status
unaffected
Version <=
7.2.*
Version
7.2.5
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.06 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/f6f04d8ae5725bcc893bdc62e3467efd97255c5b
https://git.kernel.org/stable/c/0b2615b8b54f58bbdf986dffb38cbc35214a5cc5
https://git.kernel.org/stable/c/b10cc09b329245c6d95f8fa3e7f068575e3e0e9f
https://git.kernel.org/stable/c/e4c3ab59021e7c146a84b6671f0d530972bd58b4