Description
In the Linux kernel, the following vulnerability has been resolved:

drm/amd/display: validate plane degamma LUT size for private color prop

Unlike the CRTC degamma path, which is guarded by
amdgpu_dm_verify_lut_sizes(), the per-plane degamma LUT size was never
validated before use. __set_dm_plane_degamma() passed the user-supplied
size straight into __is_lut_linear() and, for a non-linear LUT, into
__set_input_tf() -> __drm_lut_to_dc_gamma(), the latter always iterating
MAX_COLOR_LUT_ENTRIES entries regardless of the actual LUT size.

A malformed AMD_PLANE_DEGAMMA_LUT blob (e.g. a single entry) could thus
trigger a divide-by-zero in __is_lut_linear() or an out-of-bounds read in
__drm_lut_to_dc_gamma(). Reject any plane degamma LUT whose size does not
match MAX_COLOR_LUT_ENTRIES, mirroring the invariant the code already
asserts a few lines below (and which the CRTC path enforces).

The AMD_PLANE_DEGAMMA_LUT property is only exposed on builds with
AMD_PRIVATE_COLOR defined.
Published: 2026-09-16
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

This vulnerability arises from missing validation of the size of a per‑plane degamma Look‑Up Table in the AMD display driver. The driver accepts a user‑supplied size and passes it through a linearity check and a conversion routine that always iterates a fixed number of entries, regardless of the actual size. A malformed blob—such as a single entry—can therefore trigger a divide‑by‑zero during the linearity test or an out‑of‑bounds read while converting the table. The result is kernel memory corruption that can lead to a crash or, in the worst case, arbitrary code execution. The weakness is an instance of improper input validation (CWE‑20).

Affected Systems

The flaw exists in any Linux kernel that builds the AMD display driver with the AMD_PRIVATE_COLOR option enabled. The AMD_PLANE_DEGAMMA_LUT property is thus only exposed on those builds. The issue affects all architectures that compile this driver, but no specific kernel versions are listed in the advisory, so any recent kernel containing the vulnerable code path is potentially impacted.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity, while the EPSS score of less than 1 % shows a low probability of exploitation in the wild. The vulnerability is not listed in CISA's KEV catalog. The likely attack vector is local: an attacker with the ability to set the AMD_PLANE_DEGAMMA_LUT property—typically a privileged process or a user with elevated rights—can supply a malformed table and trigger the fault. The lack of bounds checking makes the crash deterministic once the malicious input is delivered, but leveraging the out‑of‑bounds read to gain code execution would require further stack or memory corruption techniques not detailed in the advisory.

Generated by OpenCVE AI on September 18, 2026 at 09:11 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the kernel to a version that includes the patch fixing the plane degamma LUT size validation; follow the commit references for guidance on the specific patches.
  • If a kernel update cannot be performed immediately, disable the AMD_PRIVATE_COLOR option or prevent setting the AMD_PLANE_DEGAMMA_LUT property, thereby blocking any use of malformed degamma tables.
  • Audit and ensure that all plane degamma LUT values are set to the exact size required by MAX_COLOR_LUT_ENTRIES and restrict modification of this property to privileged users only.

Generated by OpenCVE AI on September 18, 2026 at 09:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: validate plane degamma LUT size for private color prop Unlike the CRTC degamma path, which is guarded by amdgpu_dm_verify_lut_sizes(), the per-plane degamma LUT size was never validated before use. __set_dm_plane_degamma() passed the user-supplied size straight into __is_lut_linear() and, for a non-linear LUT, into __set_input_tf() -> __drm_lut_to_dc_gamma(), the latter always iterating MAX_COLOR_LUT_ENTRIES entries regardless of the actual LUT size. A malformed AMD_PLANE_DEGAMMA_LUT blob (e.g. a single entry) could thus trigger a divide-by-zero in __is_lut_linear() or an out-of-bounds read in __drm_lut_to_dc_gamma(). Reject any plane degamma LUT whose size does not match MAX_COLOR_LUT_ENTRIES, mirroring the invariant the code already asserts a few lines below (and which the CRTC path enforces). The AMD_PLANE_DEGAMMA_LUT property is only exposed on builds with AMD_PRIVATE_COLOR defined.
Title drm/amd/display: validate plane degamma LUT size for private color prop
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:39:00.997Z

Reserved: 2026-09-11T19:38:34.768Z

Link: CVE-2026-89819

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:47.253

Modified: 2026-09-16T15:18:11.173

Link: CVE-2026-89819

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T06:00:13Z

Weaknesses
  • CWE-20

    Improper Input Validation