CVE-2026-93179
N/A
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/powerplay: fix VoltageObjectInfo zero-stride loop and OOB read
Reject voltage objects whose usSize is smaller than the header or would advance the cursor past the table end, preventing an infinite loop or heap OOB read when the VBIOS supplies a malformed VoltageObjectInfo table.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | c82baa28184356a75c0157129f88af42b2e7b695 < 83c680de6d41d627c077dedb24f89d9e5be0e2a2 | affected |
| Linux | Linux | c82baa28184356a75c0157129f88af42b2e7b695 < 5d3cc8e388464f485d0944b87b8f9426e637d082 | affected |
| Linux | Linux | 4.5 | affected |
| Linux | Linux | 0 < 4.5 | unaffected |
| Linux | Linux | 7.2.6 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/83c680de6d41d627c077dedb24f89d9e5be0e2a2
- https://git.kernel.org/stable/c/5d3cc8e388464f485d0944b87b8f9426e637d082
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.