Description
In the Linux kernel, the following vulnerability has been resolved:

drm/amd/display: Resize MST HDCP per-connector arrays to 32

AMDGPU_DM_MAX_DISPLAY_INDEX is 31. It suggest a maximum number of
32 connectors. But the way it's used is like MAX_DISPLAY_COUNT.
Hence we're off by one with DRM core, which supports a max of 32
connectors.

Rename AMDGPU_DM_MAX_DISPLAY_INDEX to AMDGPU_DM_MAX_DISPLAY_COUNT
to match its actual use, and increase the size to 32 to match the
originally intended size.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Update Kernel
AI Analysis

Impact

The vulnerability arises from an off‑by‑one error in the AMDGPU driver where the macro AMDGPU_DM_MAX_DISPLAY_INDEX is set to 31 but the code actually expects a maximum of 32 connectors. This mismatch can cause an array index to reference one element beyond its allocated bounds, potentially leading to memory corruption. An attacker that can trigger the affected parts of the DRM subsystem could force the driver to read or write beyond the intended range, which could result in crashes or unpredictable behaviour. The description does not confirm whether the corruption could be exploited for arbitrary code execution; however, the possibility of memory corruption signifies a risk of system instability or denial of service.

Affected Systems

All Linux kernel installations that include the AMDGPU DRM driver are potentially affected. Exact kernel versions are not specified; the issue is present in the source code prior to the fix mentioned in the reference commits. Users running distributions with the default kernel should verify whether their kernel includes the updated array size of 32 elements.

Risk and Exploitability

The CVSS score of 7.8 classifies this as High severity, while the EPSS score of less than 1% indicates a very low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector would involve local user access that can invoke AMDGPU DRM operations, though remote exploitation via display protocols cannot be ruled out without further information. Given the high severity score, the potential impact, and the difficulty of proving exploitation, the overall risk is significant enough to warrant prompt patching.

Generated by OpenCVE AI on September 20, 2026 at 02:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a Linux kernel update that incorporates the driver change to resize the HDCP per‑connector arrays to 32 elements.
  • If upgrading the kernel is not yet possible, schedule a maintenance window to reboot after installing the latest package to mitigate possible instability.
  • Monitor kernel logs for DRM‑related panics or crashes that may indicate the older array size is still in use; investigate any such events immediately.

Generated by OpenCVE AI on September 20, 2026 at 02:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-129

Sat, 19 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-129

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Resize MST HDCP per-connector arrays to 32 AMDGPU_DM_MAX_DISPLAY_INDEX is 31. It suggest a maximum number of 32 connectors. But the way it's used is like MAX_DISPLAY_COUNT. Hence we're off by one with DRM core, which supports a max of 32 connectors. Rename AMDGPU_DM_MAX_DISPLAY_INDEX to AMDGPU_DM_MAX_DISPLAY_COUNT to match its actual use, and increase the size to 32 to match the originally intended size.
Title drm/amd/display: Resize MST HDCP per-connector arrays to 32
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:54:19.186Z

Reserved: 2026-09-11T19:38:34.798Z

Link: CVE-2026-90289

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:25.987

Modified: 2026-09-18T18:17:51.880

Link: CVE-2026-90289

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:45:18Z

Weaknesses

No weakness.