CVE-2026-93178: drm/amdgpu/pm/powerplay: bounds-check voltage index in SMU7 lookup
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/pm/powerplay: bounds-check voltage index in SMU7 lookup
vddInd and vddcInd fields from VBIOS-parsed tables are used to index into voltage lookup tables without a bounds check. Return -EINVAL when any index is out of range.
Event History
Frequently Asked Questions
What systems are exposed to this issue?
Systems using the Linux kernel AMDGPU PowerPlay code path for SMU7 hardware may be exposed when VBIOS-parsed voltage tables contain out-of-range vddInd or vddcInd values.
What condition is required to trigger the flaw?
The issue requires a VBIOS-parsed table with a voltage index that falls outside the corresponding voltage lookup table. The vulnerable code uses those indices without validating their bounds.
How does the fix handle invalid voltage indices?
The resolved code checks the vddInd and vddcInd values against the voltage lookup table bounds and returns -EINVAL if either index is out of range.