{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-93177","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-17T16:02:15.091Z","datePublished":"2026-09-17T16:12:05.955Z","dateUpdated":"2026-09-18T17:56:23.480Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:56:23.480Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/pm/powerplay: bounds-check voltage index in Vega10 lookup\n\nvddInd, vddciInd and mvddInd from VBIOS-parsed tables index into vddc,\nvddci and vddmem lookup tables without bounds checks across nine sites.\nReturn -EINVAL when any index is out of range."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H","baseScore":7.3,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - Writing a crafted ATOM Vega10 POWERPLAYTABLE to sysfs pp_table (amdgpu_set_pp_table → pp_dpm_set_pp_table → amd_powerplay_reset → hwmgr_hw_init) makes vega10_pp_tables_initialize copy ucVddInd/ucVddciInd/ucVddMemInd into vddInd; vega10_hwmgr_backend_init then calls vega10_patch_voltage_dependency_tables_with_lookup_table. No network protocol carries those indices.\nAC:L - The attacker fully controls ucVddInd in each ATOM_Vega10 dependency-table entry they write; get_socclk_voltage_dependency_table and get_mclk_voltage_dependency_table copy it verbatim into vddInd, and the unguarded entries[voltage_id].us_vdd load in vega10_patch_voltage_dependency_tables_with_lookup_table is deterministic with no race or victim state.\nPR:L - amdgpu_set_pp_table and pp_dpm_set_pp_table perform no capable() check; the pp_table attribute is created as S_IRUGO|S_IWUSR, and AMD desktop/handheld udev rules commonly grant group write on pp_* nodes so unprivileged overclocking tools can use them (same attribute scored PR:L in CVE-2025-21780 and CVE-2026-74450).\nUI:N - The attacker writes the malformed POWERPLAYTABLE on their own pp_table sysfs node and amd_powerplay_reset runs in that store; no other user must mount a filesystem, plug in a GPU, or open a file.\nS:U - The OOB us_vdd load and later convert_to_vid SMC programming stay inside the host amdgpu powerplay heap and Vega10 SMU tables; they do not cross a KVM/IOMMU guest-host boundary (pp_table writes are rejected for SR-IOV VFs by amdgpu_dpm_is_pp_table_allowed).\nC:H - voltage_id is a uint8_t taken from vddInd, so entries[voltage_id].us_vdd in vega10_patch_voltage_dependency_tables_with_lookup_table reads two bytes at an attacker-chosen offset of up to 255*sizeof(phm_ppt_v1_voltage_lookup_record) (~2.5KB) past a vddc_lookup_table that get_vddc_lookup_table allocated for only 8 entries (4 for vddci/vddmem).\nI:L - The OOB us_vdd is written only into in-bounds vddc/vddci/mvdd fields and later turned into SMC VIDs by convert_to_vid in vega10_populate_single_display_type and vega10_get_vdd_voltage_table, programming out-of-spec GPU rails. That is bounded power-management state corruption, not an arbitrary kernel write.\nA:H - A ~2.5KB heap overread from the kmalloc-flex lookup table can oops or KASAN-panic, and garbage millivolts converted to VID and loaded into Vega10 PPTable_t DisplayClockTable via vega10_populate_single_display_type can hang or reset the GPU."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/gpu/drm/amd/pm/powerplay/hwmgr/vega10_hwmgr.c"],"versions":[{"version":"f83a9991648bb4023a53104db699e99305890d51","lessThan":"206e478810d6af50b25d8da72e3af8d55a014365","status":"affected","versionType":"git"},{"version":"f83a9991648bb4023a53104db699e99305890d51","lessThan":"25dedc13ceb9b6109c79c92a726ca4ca017c9eaa","status":"affected","versionType":"git"},{"version":"f83a9991648bb4023a53104db699e99305890d51","lessThan":"ae25c92d91f2cb90ede2b0eb0f58efa82ccc718b","status":"affected","versionType":"git"},{"version":"f83a9991648bb4023a53104db699e99305890d51","lessThan":"b349dcf061a6dc8c6cef9a10530331ef2ff66c72","status":"affected","versionType":"git"},{"version":"f83a9991648bb4023a53104db699e99305890d51","lessThan":"dfe89f1a0c7f40ef858b93881198f9728df956cf","status":"affected","versionType":"git"},{"version":"f83a9991648bb4023a53104db699e99305890d51","lessThan":"46d27e56dbd6345b9c7b62b67ec57407bf3bf29a","status":"affected","versionType":"git"},{"version":"f83a9991648bb4023a53104db699e99305890d51","lessThan":"06aef6dcc1d52da5112cbcde39c062e493247ab5","status":"affected","versionType":"git"},{"version":"f83a9991648bb4023a53104db699e99305890d51","lessThan":"6fa33f594e46e775a94097f71b486d7b006b6917","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/gpu/drm/amd/pm/powerplay/hwmgr/vega10_hwmgr.c"],"versions":[{"version":"4.12","status":"affected"},{"version":"0","lessThan":"4.12","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/206e478810d6af50b25d8da72e3af8d55a014365"},{"url":"https://git.kernel.org/stable/c/25dedc13ceb9b6109c79c92a726ca4ca017c9eaa"},{"url":"https://git.kernel.org/stable/c/ae25c92d91f2cb90ede2b0eb0f58efa82ccc718b"},{"url":"https://git.kernel.org/stable/c/b349dcf061a6dc8c6cef9a10530331ef2ff66c72"},{"url":"https://git.kernel.org/stable/c/dfe89f1a0c7f40ef858b93881198f9728df956cf"},{"url":"https://git.kernel.org/stable/c/46d27e56dbd6345b9c7b62b67ec57407bf3bf29a"},{"url":"https://git.kernel.org/stable/c/06aef6dcc1d52da5112cbcde39c062e493247ab5"},{"url":"https://git.kernel.org/stable/c/6fa33f594e46e775a94097f71b486d7b006b6917"}],"title":"drm/amdgpu/pm/powerplay: bounds-check voltage index in Vega10 lookup","x_generator":{"engine":"bippy-1.2.0"}}}}