{"id":"CVE-2026-93177","summary":"drm/amdgpu/pm/powerplay: bounds-check voltage index in Vega10 lookup","details":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/pm/powerplay: bounds-check voltage index in Vega10 lookup\n\nvddInd, vddciInd and mvddInd from VBIOS-parsed tables index into vddc,\nvddci and vddmem lookup tables without bounds checks across nine sites.\nReturn -EINVAL when any index is out of range.","modified":"2026-09-25T18:27:31.189844625Z","published":"2026-09-17T16:12:05.955Z","related":["openSUSE-SU-2026:11880-1"],"database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93177.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/06aef6dcc1d52da5112cbcde39c062e493247ab5"},{"type":"WEB","url":"https://git.kernel.org/stable/c/206e478810d6af50b25d8da72e3af8d55a014365"},{"type":"WEB","url":"https://git.kernel.org/stable/c/25dedc13ceb9b6109c79c92a726ca4ca017c9eaa"},{"type":"WEB","url":"https://git.kernel.org/stable/c/46d27e56dbd6345b9c7b62b67ec57407bf3bf29a"},{"type":"WEB","url":"https://git.kernel.org/stable/c/6fa33f594e46e775a94097f71b486d7b006b6917"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ae25c92d91f2cb90ede2b0eb0f58efa82ccc718b"},{"type":"WEB","url":"https://git.kernel.org/stable/c/b349dcf061a6dc8c6cef9a10530331ef2ff66c72"},{"type":"WEB","url":"https://git.kernel.org/stable/c/dfe89f1a0c7f40ef858b93881198f9728df956cf"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93177.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93177"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"f83a9991648bb4023a53104db699e99305890d51"},{"fixed":"206e478810d6af50b25d8da72e3af8d55a014365"},{"fixed":"25dedc13ceb9b6109c79c92a726ca4ca017c9eaa"},{"fixed":"ae25c92d91f2cb90ede2b0eb0f58efa82ccc718b"},{"fixed":"b349dcf061a6dc8c6cef9a10530331ef2ff66c72"},{"fixed":"dfe89f1a0c7f40ef858b93881198f9728df956cf"},{"fixed":"46d27e56dbd6345b9c7b62b67ec57407bf3bf29a"},{"fixed":"06aef6dcc1d52da5112cbcde39c062e493247ab5"},{"fixed":"6fa33f594e46e775a94097f71b486d7b006b6917"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-93177.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.12.0"},{"fixed":"5.10.270"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.221"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.188"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.157"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.110"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.52"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.2.6"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-93177.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H"}]}