CVE-2025-38091: drm/amd/display: check stream id dml21 wrapper to get plane_id
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: check stream id dml21 wrapper to get planeid
[Why & How] Fix a false positive warning which occurs due to lack of correct checks when querying planeid in DML21. This fixes the warning when performing a mode1 reset (cat /sys/kernel/debug/dri/1/amdgpugpurecover):
[ 35.751250] WARNING: CPU: 11 PID: 326 at /tmp/amd.PHpyAl7v/amd/amdgpu/../display/dc/dml2/dml2dcresourcemgmt.c:91 dml2mapdcpipes+0x243d/0x3f40 [amdgpu] [ 35.751434] Modules linked in: amdgpu(OE) amddrmttmhelper(OE) amdttm(OE) amddrmbuddy(OE) amdxcp(OE) amddrmexec(OE) amdsched(OE) amdkcl(OE) drmsuballochelper drmttmhelper ttm drmdisplayhelper cec rccore i2calgobit rfcomm qrtr cmac algifhash algifskcipher afalg bnep amdatl intelraplmsr intelraplcommon sndhdacodechdmi sndhdaintel edacmceamd sndinteldspcfg sndintelsdwacpi sndhdacodec kvmamd sndhdacore sndhwdep sndpcm kvm sndseqmidi sndseqmidievent sndrawmidi crct10difpclmul polyvalclmulni polyvalgeneric btusb ghashclmulniintel sha256ssse3 btrtl sha1ssse3 sndseq btintel aesniintel btbcm btmtk sndseqdevice cryptosimd sunrpc cryptd bluetooth sndtimer ccp binfmtmisc rapl snd i2cpiix4 wmibmof gigabytewmi k10temp i2csmbus soundcore gpioamdpt machid schfqcodel msr parportpc ppdev lp parport efipstore nfnetlink dmisysfs iptables xtables autofs4 hidgeneric usbhid hid crc32pclmul igc ahci xhcipci libahci xhcipcirenesas video wmi [ 35.751501] CPU: 11 UID: 0 PID: 326 Comm: kworker/u64:9 Tainted: G OE 6.11.0-21-generic #21~24.04.1-Ubuntu [ 35.751504] Tainted: [O]=OOTMODULE, [E]=UNSIGNEDMODULE [ 35.751505] Hardware name: Gigabyte Technology Co., Ltd. X670E AORUS PRO X/X670E AORUS PRO X, BIOS F30 05/22/2024 [ 35.751506] Workqueue: amdgpu-reset-dev amdgpudebugfsresetwork [amdgpu] [ 35.751638] RIP: 0010:dml2mapdcpipes+0x243d/0x3f40 [amdgpu] [ 35.751794] Code: 6d 0c 00 00 8b 84 24 88 00 00 00 41 3b 44 9c 20 0f 84 fc 07 00 00 48 83 c3 01 48 83 fb 06 75 b3 4c 8b 64 24 68 4c 8b 6c 24 40 <0f> 0b b8 06 00 00 00 49 8b 94 24 a0 49 00 00 89 c3 83 f8 07 0f 87 [ 35.751796] RSP: 0018:ffffbfa3805d7680 EFLAGS: 00010246 [ 35.751798] RAX: 0000000000010000 RBX: 0000000000000006 RCX: 0000000000000000 [ 35.751799] RDX: 0000000000000000 RSI: 0000000000000005 RDI: 0000000000000000 [ 35.751800] RBP: ffffbfa3805d78f0 R08: 0000000000000000 R09: 0000000000000000 [ 35.751801] R10: 0000000000000000 R11: 0000000000000000 R12: ffffbfa383249000 [ 35.751802] R13: ffffa0e68f280000 R14: ffffbfa383249658 R15: 0000000000000000 [ 35.751803] FS: 0000000000000000(0000) GS:ffffa0edbe580000(0000) knlGS:0000000000000000 [ 35.751804] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 35.751805] CR2: 00005d847ef96c58 CR3: 000000041de3e000 CR4: 0000000000f50ef0 [ 35.751806] PKRU: 55555554 [ 35.751807] Call Trace: [ 35.751810] <TASK> [ 35.751816] ? showregs+0x6c/0x80 [ 35.751820] ? warn+0x88/0x140 [ 35.751822] ? dml2mapdcpipes+0x243d/0x3f40 [amdgpu] [ 35.751964] ? reportbug+0x182/0x1b0 [ 35.751969] ? handlebug+0x6e/0xb0 [ 35.751972] ? excinvalidop+0x18/0x80 [ 35.751974] ? asmexcinvalidop+0x1b/0x20 [ 35.751978] ? dml2mapdcpipes+0x243d/0x3f40 [amdgpu] [ 35.752117] ? mathpow+0x48/0xa0 [amdgpu] [ 35.752256] ? srsoaliasreturnthunk+0x5/0xfbef5 [ 35.752260] ? mathpow+0x48/0xa0 [amdgpu] [ 35.752400] ? srsoaliasreturnthunk+0x5/0xfbef5 [ 35.752403] ? mathpow+0x11/0xa0 [amdgpu] [ 35.752524] ? srsoaliasreturnthunk+0x5/0xfbef5 [ 35.752526] ? coredcn4modeprogramming+0xe4d/0x20d0 [amdgpu] [ 35.752663] ? srsoaliasreturnthunk+0x5/0xfbef5 [ 35.752669] dml21validate+0x3d4/0x980 [amdgpu]
(cherry picked from commit f8ad62c0a93e5dd94243e10f1b742232e4d6411e)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-38091?
CVE-2025-38091 has a moderate severity level due to the potential for false positive warnings in the Linux kernel.
How do I fix CVE-2025-38091?
To fix CVE-2025-38091, ensure your Linux kernel is updated to the latest stable version that includes the patch addressing this vulnerability.
What systems are affected by CVE-2025-38091?
CVE-2025-38091 affects various versions of the Linux kernel that use the AMD display drivers.
What does CVE-2025-38091 specifically address?
CVE-2025-38091 specifically addresses a flaw related to the lack of correct checks when querying plane_id in the DML21 wrapper for AMD display.
Was CVE-2025-38091 exploited in the wild?
As of now, there is no public information indicating that CVE-2025-38091 has been exploited in the wild.