CVE-2026-93177

Source
https://cve.org/CVERecord?id=CVE-2026-93177
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93177.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-93177
Downstream
Published
2026-09-17T16:12:05Z
Modified
2026-09-18T03:47:37Z
Summary
drm/amdgpu/pm/powerplay: bounds-check voltage index in Vega10 lookup
Details

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu/pm/powerplay: bounds-check voltage index in Vega10 lookup

vddInd, vddciInd and mvddInd from VBIOS-parsed tables index into vddc, vddci and vddmem lookup tables without bounds checks across nine sites. Return -EINVAL when any index is out of range.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93177.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
f83a9991648bb4023a53104db699e99305890d51
Fixed
206e478810d6af50b25d8da72e3af8d55a014365
Fixed
25dedc13ceb9b6109c79c92a726ca4ca017c9eaa
Fixed
ae25c92d91f2cb90ede2b0eb0f58efa82ccc718b
Fixed
b349dcf061a6dc8c6cef9a10530331ef2ff66c72
Fixed
dfe89f1a0c7f40ef858b93881198f9728df956cf
Fixed
46d27e56dbd6345b9c7b62b67ec57407bf3bf29a
Fixed
06aef6dcc1d52da5112cbcde39c062e493247ab5
Fixed
6fa33f594e46e775a94097f71b486d7b006b6917

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93177.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.12.0
Fixed
5.10.270
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93177.json"