7.8

CVE-2026-89819

drm/amd/display: validate plane degamma LUT size for private color prop

In the Linux kernel, the following vulnerability has been resolved:

drm/amd/display: validate plane degamma LUT size for private color prop

Unlike the CRTC degamma path, which is guarded by
amdgpu_dm_verify_lut_sizes(), the per-plane degamma LUT size was never
validated before use. __set_dm_plane_degamma() passed the user-supplied
size straight into __is_lut_linear() and, for a non-linear LUT, into
__set_input_tf() -> __drm_lut_to_dc_gamma(), the latter always iterating
MAX_COLOR_LUT_ENTRIES entries regardless of the actual LUT size.

A malformed AMD_PLANE_DEGAMMA_LUT blob (e.g. a single entry) could thus
trigger a divide-by-zero in __is_lut_linear() or an out-of-bounds read in
__drm_lut_to_dc_gamma(). Reject any plane degamma LUT whose size does not
match MAX_COLOR_LUT_ENTRIES, mirroring the invariant the code already
asserts a few lines below (and which the CRTC path enforces).

The AMD_PLANE_DEGAMMA_LUT property is only exposed on builds with
AMD_PRIVATE_COLOR defined.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 980f8710075acaeb226a94cde6dda8ffad30123c
Version < f6f04d8ae5725bcc893bdc62e3467efd97255c5b
Status affected
Version 980f8710075acaeb226a94cde6dda8ffad30123c
Version < 0b2615b8b54f58bbdf986dffb38cbc35214a5cc5
Status affected
Version 980f8710075acaeb226a94cde6dda8ffad30123c
Version < b10cc09b329245c6d95f8fa3e7f068575e3e0e9f
Status affected
Version 980f8710075acaeb226a94cde6dda8ffad30123c
Version < e4c3ab59021e7c146a84b6671f0d530972bd58b4
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.8
Status affected
Version 0
Version < 6.8
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.51
Status unaffected
Version <= 7.2.*
Version 7.2.5
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.06
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/f6f04d8ae5725bcc893bdc62e3467efd97255c5b
https://git.kernel.org/stable/c/0b2615b8b54f58bbdf986dffb38cbc35214a5cc5
https://git.kernel.org/stable/c/b10cc09b329245c6d95f8fa3e7f068575e3e0e9f
https://git.kernel.org/stable/c/e4c3ab59021e7c146a84b6671f0d530972bd58b4