CVE-2026-93177: drm/amdgpu/pm/powerplay: bounds-check voltage index in Vega10 lookup
Published Sep 17, 2026
·Updated
drm/amdgpu/pm/powerplay: bounds-check voltage index in Vega10 lookup
Affected Software
2 affected componentsFixes available
Linux Kernel
Microsoft azl3 kernel 6.6.152.1-1<6.6.157.1-1
6.6.157.1-1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.157.1-1
Event History
Sep 17, 2026
CVE Published
via MITRE·04:12 PM
Data Sourced
via MITRE·04:12 PM
DescriptionSeverity
Data Sourced
via NVD·05:18 PM
DescriptionSeverity
Sep 19, 2026
Data Sourced
via Microsoft·08:13 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:13 AM
DescriptionSeverity
Frequently Asked Questions
1
Which systems are exposed to this issue?
Exposure is limited to Linux kernel systems using the AMDGPU PowerPlay path for Vega10, where VBIOS-parsed voltage-table indices are used.
2
What condition is required to trigger the flaw?
The VBIOS-parsed tables must contain an out-of-range vddInd, vddciInd, or mvddInd value that is used to index the corresponding voltage lookup table.
3
How can affected systems be identified or mitigated before patching?
The provided data does not describe a detection method or workaround. The fix changes the affected lookup sites to reject invalid indices with -EINVAL.