Description
In the Linux kernel, the following vulnerability has been resolved:

drm/lima: call drm_mm_init() with a valid allocation range

lima_vm_create() is currently run before va_start and va_end are set up,
meaning they are both 0. lima_vm_create() runs drm_mm_init() with them
as arguments for the allocator, and if DRM_DEBUG_MM is enabled the
DRM_MM_BUG_ON check in drm_mm_init then fires, as seen here on
exynos4412-odroid-u2:

[ 1.736297] ------------[ cut here ]------------
[ 1.740370] kernel BUG at drivers/gpu/drm/drm_mm.c:931!
[ 1.745574] Internal error: Oops - BUG: 0 [#1] SMP ARM
[ 1.750697] Modules linked in:
[ 1.753734] CPU: 0 UID: 0 PID: 41 Comm: kworker/u16:1 Not tainted 7.0.10-postmarketos-exynos4 #11 PREEMPT
[ 1.763372] Hardware name: Samsung Exynos (Flattened Device Tree)
[ 1.769446] Workqueue: events_unbound deferred_probe_work_func
[ 1.775261] PC is at drm_mm_init+0x9c/0xa4
[ 1.779339] LR is at lima_vm_create+0x144/0x17c
[ ... ]

Fix the issue by moving the lima_vm_create() call after va_start and
va_end are set up.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via kernel panic
Action: Patch
AI Analysis

Impact

A defect in the Linux kernel’s Lima DRM driver causes the allocator drm_mm_init to be called before the virtual address range is initialized, leading to a kernel assertion failure and a system crash. The failure occurs when va_start and va_end remain zero, so drm_mm_init receives an invalid range and triggers a BUG. The consequence is a kernel panic that disrupts system operation and results in a loss of availability.

Affected Systems

All Linux kernel releases that include the Lima DRM driver are affected, including the 7.0.10-postmarketos-exynos4 kernel and other versions using the same buggy sequence. The issue is specific to systems that load the Lima driver during boot or device initialization.

Risk and Exploitability

The EPSS score is below 1%, indicating a very low probability of exploitation as reflected in current data. The flaw does not provide a remote code‑execution path; it requires interaction with the device driver during initialization. The vulnerability is not listed in the CISA KEV catalog, and no CVSS score is supplied, but the kernel panic demonstrates a high impact on availability for affected systems.

Generated by OpenCVE AI on September 19, 2026 at 08:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that includes the fix that moves the lima_vm_create call after va_start and va_end are set up
  • If an immediate kernel update is not available, disable or unload the Lima DRM driver to prevent the faulty initialization
  • Verify system logs for any occurrences of drm_mm_init or kernel BUG messages; investigate and remediate any pending driver load failures

Generated by OpenCVE AI on September 19, 2026 at 08:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm/lima: call drm_mm_init() with a valid allocation range lima_vm_create() is currently run before va_start and va_end are set up, meaning they are both 0. lima_vm_create() runs drm_mm_init() with them as arguments for the allocator, and if DRM_DEBUG_MM is enabled the DRM_MM_BUG_ON check in drm_mm_init then fires, as seen here on exynos4412-odroid-u2: [ 1.736297] ------------[ cut here ]------------ [ 1.740370] kernel BUG at drivers/gpu/drm/drm_mm.c:931! [ 1.745574] Internal error: Oops - BUG: 0 [#1] SMP ARM [ 1.750697] Modules linked in: [ 1.753734] CPU: 0 UID: 0 PID: 41 Comm: kworker/u16:1 Not tainted 7.0.10-postmarketos-exynos4 #11 PREEMPT [ 1.763372] Hardware name: Samsung Exynos (Flattened Device Tree) [ 1.769446] Workqueue: events_unbound deferred_probe_work_func [ 1.775261] PC is at drm_mm_init+0x9c/0xa4 [ 1.779339] LR is at lima_vm_create+0x144/0x17c [ ... ] Fix the issue by moving the lima_vm_create() call after va_start and va_end are set up.
Title drm/lima: call drm_mm_init() with a valid allocation range
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:12:10.072Z

Reserved: 2026-09-17T16:02:15.091Z

Link: CVE-2026-93183

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:14.290

Modified: 2026-09-17T17:18:14.290

Link: CVE-2026-93183

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T06:45:17Z

Weaknesses