drm/lima: call drm_mm_init() with a valid allocation range
Summary
| CVE | CVE-2026-93183 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-17 17:18:14 UTC |
| Updated | 2026-09-17 17:18:14 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: drm/lima: call drm_mm_init() with a valid allocation range lima_vm_create() is currently run before va_start and va_end are set up, meaning they are both 0. lima_vm_create() runs drm_mm_init() with them as arguments for the allocator, and if DRM_DEBUG_MM is enabled the DRM_MM_BUG_ON check in drm_mm_init then fires, as seen here on exynos4412-odroid-u2: [ 1.736297] ------------[ cut here ]------------ [ 1.740370] kernel BUG at drivers/gpu/drm/drm_mm.c:931! [ 1.745574] Internal error: Oops - BUG: 0 [#1] SMP ARM [ 1.750697] Modules linked in: [ 1.753734] CPU: 0 UID: 0 PID: 41 Comm: kworker/u16:1 Not tainted 7.0.10-postmarketos-exynos4 #11 PREEMPT [ 1.763372] Hardware name: Samsung Exynos (Flattened Device Tree) [ 1.769446] Workqueue: events_unbound deferred_probe_work_func [ 1.775261] PC is at drm_mm_init+0x9c/0xa4 [ 1.779339] LR is at lima_vm_create+0x144/0x17c [ ... ] Fix the issue by moving the lima_vm_create() call after va_start and va_end are set up. |
Risk And Classification
EPSS: 0.002110000 probability, percentile 0.116290000 (date 2026-09-19)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected a1d2a6339961efc078208dc3b2f006e9e9a8e119 af1f276d50c9d7ebcd25770f358ca503a89d96d7 git | Not specified |
| CNA | Linux | Linux | affected a1d2a6339961efc078208dc3b2f006e9e9a8e119 fd6bc5f1d6b54047b06b82bab25a7e21e4b1c95a git | Not specified |
| CNA | Linux | Linux | affected a1d2a6339961efc078208dc3b2f006e9e9a8e119 ad4e908096dff97646f77b04e2e2825225e215f7 git | Not specified |
| CNA | Linux | Linux | affected a1d2a6339961efc078208dc3b2f006e9e9a8e119 788917ba77f5d69bd368c1d176ecceda346a2951 git | Not specified |
| CNA | Linux | Linux | affected a1d2a6339961efc078208dc3b2f006e9e9a8e119 79a3331ee436c8b1454f897d539606c9b5ebdf9f git | Not specified |
| CNA | Linux | Linux | affected a1d2a6339961efc078208dc3b2f006e9e9a8e119 e2a7cee341986cb5b544a8286edc7fb0494c592e git | Not specified |
| CNA | Linux | Linux | affected a1d2a6339961efc078208dc3b2f006e9e9a8e119 e0773ad25a34a49aece176721c466cf214e02222 git | Not specified |
| CNA | Linux | Linux | affected a1d2a6339961efc078208dc3b2f006e9e9a8e119 3b3bce4a692ac60d9f4a341e6b597dd1fd0a28f9 git | Not specified |
| CNA | Linux | Linux | affected 5.2 | Not specified |
| CNA | Linux | Linux | unaffected 5.2 semver | Not specified |
| CNA | Linux | Linux | unaffected 5.10.270 5.10.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.221 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.188 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.157 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.110 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.52 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2.6 7.2.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.3-rc1 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/e0773ad25a34a49aece176721c466cf214e02222 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/e2a7cee341986cb5b544a8286edc7fb0494c592e | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/79a3331ee436c8b1454f897d539606c9b5ebdf9f | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/788917ba77f5d69bd368c1d176ecceda346a2951 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/af1f276d50c9d7ebcd25770f358ca503a89d96d7 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/3b3bce4a692ac60d9f4a341e6b597dd1fd0a28f9 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/ad4e908096dff97646f77b04e2e2825225e215f7 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/fd6bc5f1d6b54047b06b82bab25a7e21e4b1c95a | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.