CVE-2026-93178

Source
https://cve.org/CVERecord?id=CVE-2026-93178
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93178.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-93178
Downstream
Published
2026-09-17T16:12:06Z
Modified
2026-09-18T03:48:44Z
Summary
drm/amdgpu/pm/powerplay: bounds-check voltage index in SMU7 lookup
Details

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu/pm/powerplay: bounds-check voltage index in SMU7 lookup

vddInd and vddcInd fields from VBIOS-parsed tables are used to index into voltage lookup tables without a bounds check. Return -EINVAL when any index is out of range.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93178.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
c82baa28184356a75c0157129f88af42b2e7b695
Fixed
d9ef085114d1e3c2c1f869c0bdb275a7b358ce8b
Fixed
6f08c001fa6e8212930d694540ae8d9d6d3fb58a
Fixed
ce0d8e72836c9d3710a160ad848b0f1d096075e3
Fixed
745297208d31222f916cc04da313cb737b997935
Fixed
f925d317d84d401d642e537ea18ee12f67cb6983
Fixed
8a3db9f593b643904c6cc6d8a3f211c84ca6cf8a
Fixed
1664327ce797e09e387dc10cbbaa5b8d76558d2c
Fixed
3a8a05477cda6c8293e2b629495b42981dcaba32

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93178.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.5.0
Fixed
5.10.270
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93178.json"