CVE-2026-93179

Source
https://cve.org/CVERecord?id=CVE-2026-93179
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93179.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-93179
Downstream
Published
2026-09-17T16:12:07Z
Modified
2026-09-19T03:47:22Z
Summary
drm/amd/powerplay: fix VoltageObjectInfo zero-stride loop and OOB read
Details

In the Linux kernel, the following vulnerability has been resolved:

drm/amd/powerplay: fix VoltageObjectInfo zero-stride loop and OOB read

Reject voltage objects whose usSize is smaller than the header or would advance the cursor past the table end, preventing an infinite loop or heap OOB read when the VBIOS supplies a malformed VoltageObjectInfo table.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93179.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
c82baa28184356a75c0157129f88af42b2e7b695
Fixed
83c680de6d41d627c077dedb24f89d9e5be0e2a2
Fixed
5d3cc8e388464f485d0944b87b8f9426e637d082

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93179.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.5.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93179.json"