Description
In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu/pm/powerplay: bounds-check voltage index in Vega10 lookup

vddInd, vddciInd and mvddInd from VBIOS-parsed tables index into vddc,
vddci and vddmem lookup tables without bounds checks across nine sites.
Return -EINVAL when any index is out of range.
Published: 2026-09-17
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via driver failure
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from a missing bounds check on voltage index tables in the Linux amdgpu driver’s powerplay subsystem. Indices parsed from the VBIOS are used to look up voltage settings without verifying that they fall within the bounds of the corresponding lookup tables. When an out‑of‑range index is supplied the driver returns –EINVAL, which can cause the GPU power‑management functions to fail or hang. The weakness is an out‑of‑bounds memory access and the impact is a denial of service to the GPU power‑management path. Based on the description, the likely attack vector requires local access to the system’s GPU firmware; installing a crafted or maliciously signed VBIOS image could trigger the failure.

Affected Systems

Linux kernel distributions that ship the amdgpu driver and contain the vulnerable powerplay code. Any kernel version prior to the patched release is affected; the exact affected build numbers are not specified in the data. They correspond to the Linux:Linux vendor/product pair.

Risk and Exploitability

The single‑point failure caused by the unchecked voltage index can lead to a GPU driver crash or a deadlock in power‑management, effectively interrupting GPU availability and potentially the broader system if the driver is essential. The CVSS score of 7.3 indicates a high severity. With a VBIOS image under the attacker’s control, local exploitation is feasible. However, the very low EPSS score (<1%) and the absence from KEV suggest that exploitation is unlikely in the wild at this time, but the inherent local nature of the attack means readiness to mitigate is prudent.

Generated by OpenCVE AI on September 20, 2026 at 02:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel update that includes the bounds‑check patch for the amdgpu driver.
  • If a kernel upgrade is not immediately possible, unload or disable the amdgpu module to prevent the vulnerable code from executing.
  • Ensure that GPU firmware images are signed and authenticated before installation to avoid malicious VBIOS modification.

Generated by OpenCVE AI on September 20, 2026 at 02:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 03:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-788

Sun, 20 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-788

Sat, 19 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-788

Sat, 19 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-788

Sat, 19 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-788

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/pm/powerplay: bounds-check voltage index in Vega10 lookup vddInd, vddciInd and mvddInd from VBIOS-parsed tables index into vddc, vddci and vddmem lookup tables without bounds checks across nine sites. Return -EINVAL when any index is out of range.
Title drm/amdgpu/pm/powerplay: bounds-check voltage index in Vega10 lookup
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:56:23.480Z

Reserved: 2026-09-17T16:02:15.091Z

Link: CVE-2026-93177

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:13.500

Modified: 2026-09-18T18:18:23.783

Link: CVE-2026-93177

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T03:00:11Z

Weaknesses
  • CWE-788

    Access of Memory Location After End of Buffer