{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90289","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.798Z","datePublished":"2026-09-17T16:08:17.368Z","dateUpdated":"2026-09-18T17:54:19.186Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:54:19.186Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Resize MST HDCP per-connector arrays to 32\n\nAMDGPU_DM_MAX_DISPLAY_INDEX is 31. It suggest a maximum number of\n32 connectors. But the way it's used is like MAX_DISPLAY_COUNT.\nHence we're off by one with DRM core, which supports a max of 32\nconnectors.\n\nRename AMDGPU_DM_MAX_DISPLAY_INDEX to AMDGPU_DM_MAX_DISPLAY_COUNT\nto match its actual use, and increase the size to 32 to match the\noriginally intended size."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - hdcp_update_display() and update_config() index hdcp_workqueue.aconnector[] with aconnector->base.index from drm_connector_init_only()'s ida_alloc_max(..., 31). The path is DRM_IOCTL_MODE_ATOMIC → drm_mode_atomic_ioctl → amdgpu_dm_atomic_commit_tail → amdgpu_dm_update_hdcp()/update_psp_stream_config(); dm_dp_mst_get_modes() is reached from DRM_IOCTL_MODE_GETCONNECTOR. The index is kernel-assigned, not a protocol field.\nAC:L - No race or layout lottery: drm_connector_init_only() can assign index 31, and dm_dp_add_mst_connector() creates MST connectors until that id is used. A DRM-master atomic commit that enables that connector calls update_config(), which does hdcp_w->aconnector[conn_index] with no bounds check. hdcp_create_workqueue() is created by default on Raven-and-later GPUs.\nPR:L - drm_mode_atomic_ioctl and drm_mode_obj_set_property_ioctl are DRM_MASTER in drm_ioctl.c; drm_mode_getconnector() only calls fill_modes when drm_is_current_master(). logind grants DRM master to the seated unprivileged video/render-group user on typical AMDGPU desktops, laptops, and cloud GPU instances, so init-namespace root is not required.\nUI:N - The DRM-master attacker triggers the OOB with their own DRM_IOCTL_MODE_ATOMIC (stream enable through update_psp_stream_config(), or Content Protection via amdgpu_dm_update_hdcp()) on the index-31 connector; no other user must mount media, open a file, or attach a display on the attacker's behalf.\nS:U - aconnector[31] overwrites the following hdcp_workqueue.mutex in the same host-kernel AMDGPU HDCP object; the corruption and any oops stay inside that kernel authority and do not cross a KVM/Xen, IOMMU, or sandbox boundary.\nC:H - hdcp_update_display() holds hdcp_w->mutex then reads aconnector[31], which overlays mutex.owner (the locked task_struct *). A non-NULL owner is treated as amdgpu_dm_connector * and drm_connector_put(&...->base) follows it. dm_dp_mst_get_modes() also copies hdcp_content_type[31]/content_protection[31] into connector state readable via GETCONNECTOR.\nI:H - hdcp_update_display() and update_config() write aconnector[31]=aconnector, storing an amdgpu_dm_connector * over mutex.owner while the lock is held. amdgpu_dm_update_hdcp() also writes hdcp_content_type[connector->index] and content_protection[connector->index] on MST. That is an out-of-bounds write into adjacent hdcp_workqueue fields.\nA:H - drm_connector_put() on mutex.owner type-confused as amdgpu_dm_connector, and later lock operations on a mutex whose owner was replaced by a connector pointer, oops or panic the kernel in amdgpu_dm_atomic_commit_tail/HDCP workqueue paths."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_hdcp.c","drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_hdcp.h"],"versions":[{"version":"82986fd631fa04bcedaefe11a6b3767601cbe84f","lessThan":"0fa116a17b69a28712cdf209318e345b676d7f6c","status":"affected","versionType":"git"},{"version":"82986fd631fa04bcedaefe11a6b3767601cbe84f","lessThan":"261e0fe4e2c99f687114b64b10b98db964b475f4","status":"affected","versionType":"git"},{"version":"99c444d3c3c43db354b253d9bfac081073dcb484","status":"affected","versionType":"git"},{"version":"d90f97cb3821c47bdf773dcf6cade143773ec764","status":"affected","versionType":"git"},{"version":"5.15.128","lessThan":"5.16","status":"affected","versionType":"semver"},{"version":"6.1.47","lessThan":"6.2","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_hdcp.c","drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_hdcp.h"],"versions":[{"version":"6.3","status":"affected"},{"version":"0","lessThan":"6.3","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.3","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.3","versionEndExcluding":"7.3-rc1"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15.128"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.1.47"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/0fa116a17b69a28712cdf209318e345b676d7f6c"},{"url":"https://git.kernel.org/stable/c/261e0fe4e2c99f687114b64b10b98db964b475f4"}],"title":"drm/amd/display: Resize MST HDCP per-connector arrays to 32","x_generator":{"engine":"bippy-1.2.0"}}}}