CVE-2026-93139
N/A
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/mes: Fix hung_queue_db_array loop limit for multi-XCC
The loop iterated only AMDGPU_MAX_MES_PIPES times, leaving entries uninitialized for multi-XCC GPUs. This causes null pointer dereferences when accessing arrays indexed by XCC ID >= 2. Extend the loop to cover all XCCs (AMDGPU_MAX_MES_PIPES * num_xcc), matching other per-XCC arrays.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | a132fc9bc2f8b394a2f75947a0e1f5c22482a94c < 7ff668cfc3960ed5b944ac35129f18a15ea08b74 | affected |
| Linux | Linux | a132fc9bc2f8b394a2f75947a0e1f5c22482a94c < 2c256086a363f01f9840a57949506eccf5c990a6 | affected |
| Linux | Linux | 7.2 | affected |
| Linux | Linux | 0 < 7.2 | unaffected |
| Linux | Linux | 7.2.6 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/7ff668cfc3960ed5b944ac35129f18a15ea08b74
- https://git.kernel.org/stable/c/2c256086a363f01f9840a57949506eccf5c990a6
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.