Description
In the Linux kernel, the following vulnerability has been resolved:

drm/amd/display: Add signal type check for dcn401 get_phyd32clk_src

Trying to access link enc on a dpia link will cause a crash otherwise
Published: 2026-05-06
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A missing signal type check in the dcn401 get_phyd32clk_src function within the drm/amd/display component causes an unhandled memory access when attempting to retrieve the link encoder on a DPIA link, resulting in a kernel crash and a loss of service. This flaw is a local issue that leads only to a denial of service, with no documented ability to execute arbitrary code or elevate privileges beyond the kernel context. The crash disrupts normal operation of the display subsystem, potentially rendering the system unusable until rebooted.

Affected Systems

The vulnerability affects the Linux kernel implementation of DRM for AMD display hardware. All distributions shipping an unpatched kernel that includes the drm/amd/display subsystem are potentially impacted, regardless of the distribution vendor. No specific kernel version or release is listed, so any kernel prior to the patch that incorporates the failing code path is at risk.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate severity, while the EPSS score of < 1% suggests a very low probability of exploitation. The flaw is not listed in the CISA KEV catalog, indicating that no known active exploit exists. A local user with sufficient privileges could trigger the kernel crash by attempting to access the link encoder on a DPIA link, leading to a denial of service that may render the system unusable until rebooted. Overall risk remains moderate and is confined to local denial of service unless other vulnerabilities are chained.

Generated by OpenCVE AI on May 11, 2026 at 19:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel update that contains the patch for dcn401 get_phyd32clk_src, addressing untrusted input handling (CWE‑1287).
  • If an update is not immediately available, disable DPIA display functionality or prevent loading of the drm/amd/display module to avoid the crash, which also mitigates the untrusted input vulnerability (CWE‑1287).
  • Restrict privileged access to the DRM subsystem by ensuring only authorized users are in the video or drm groups, reducing the likelihood of local denial-of-service and monitoring kernel logs for related crashes to detect any attempts to trigger the flaw.

Generated by OpenCVE AI on May 11, 2026 at 19:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 11 May 2026 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Mon, 11 May 2026 15:15:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Thu, 07 May 2026 00:15:00 +0000


Wed, 06 May 2026 15:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Wed, 06 May 2026 12:15:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Add signal type check for dcn401 get_phyd32clk_src Trying to access link enc on a dpia link will cause a crash otherwise
Title drm/amd/display: Add signal type check for dcn401 get_phyd32clk_src
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-05-11T22:20:46.641Z

Reserved: 2026-05-01T14:12:55.995Z

Link: CVE-2026-43243

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-05-06T12:16:44.720

Modified: 2026-05-11T14:16:58.187

Link: CVE-2026-43243

cve-icon Redhat

Severity :

Publid Date: 2026-05-06T00:00:00Z

Links: CVE-2026-43243 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-05-11T19:45:08Z