{"api_version":"1","generated_at":"2026-10-02T21:36:54+00:00","cve":"CVE-2026-89819","urls":{"html":"https://cve.report/CVE-2026-89819","api":"https://cve.report/api/cve/CVE-2026-89819.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-89819","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-89819"},"summary":{"title":"drm/amd/display: validate plane degamma LUT size for private color prop","description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: validate plane degamma LUT size for private color prop\n\nUnlike the CRTC degamma path, which is guarded by\namdgpu_dm_verify_lut_sizes(), the per-plane degamma LUT size was never\nvalidated before use. __set_dm_plane_degamma() passed the user-supplied\nsize straight into __is_lut_linear() and, for a non-linear LUT, into\n__set_input_tf() -> __drm_lut_to_dc_gamma(), the latter always iterating\nMAX_COLOR_LUT_ENTRIES entries regardless of the actual LUT size.\n\nA malformed AMD_PLANE_DEGAMMA_LUT blob (e.g. a single entry) could thus\ntrigger a divide-by-zero in __is_lut_linear() or an out-of-bounds read in\n__drm_lut_to_dc_gamma(). Reject any plane degamma LUT whose size does not\nmatch MAX_COLOR_LUT_ENTRIES, mirroring the invariant the code already\nasserts a few lines below (and which the CRTC path enforces).\n\nThe AMD_PLANE_DEGAMMA_LUT property is only exposed on builds with\nAMD_PRIVATE_COLOR defined.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-16 11:16:47","updated_at":"2026-09-16 15:18:11"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/f6f04d8ae5725bcc893bdc62e3467efd97255c5b","name":"https://git.kernel.org/stable/c/f6f04d8ae5725bcc893bdc62e3467efd97255c5b","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/e4c3ab59021e7c146a84b6671f0d530972bd58b4","name":"https://git.kernel.org/stable/c/e4c3ab59021e7c146a84b6671f0d530972bd58b4","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/0b2615b8b54f58bbdf986dffb38cbc35214a5cc5","name":"https://git.kernel.org/stable/c/0b2615b8b54f58bbdf986dffb38cbc35214a5cc5","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/b10cc09b329245c6d95f8fa3e7f068575e3e0e9f","name":"https://git.kernel.org/stable/c/b10cc09b329245c6d95f8fa3e7f068575e3e0e9f","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89819","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89819","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 980f8710075acaeb226a94cde6dda8ffad30123c f6f04d8ae5725bcc893bdc62e3467efd97255c5b git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 980f8710075acaeb226a94cde6dda8ffad30123c 0b2615b8b54f58bbdf986dffb38cbc35214a5cc5 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 980f8710075acaeb226a94cde6dda8ffad30123c b10cc09b329245c6d95f8fa3e7f068575e3e0e9f git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 980f8710075acaeb226a94cde6dda8ffad30123c e4c3ab59021e7c146a84b6671f0d530972bd58b4 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.8","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.8 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.110 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.51 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.5 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_color.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"f6f04d8ae5725bcc893bdc62e3467efd97255c5b","status":"affected","version":"980f8710075acaeb226a94cde6dda8ffad30123c","versionType":"git"},{"lessThan":"0b2615b8b54f58bbdf986dffb38cbc35214a5cc5","status":"affected","version":"980f8710075acaeb226a94cde6dda8ffad30123c","versionType":"git"},{"lessThan":"b10cc09b329245c6d95f8fa3e7f068575e3e0e9f","status":"affected","version":"980f8710075acaeb226a94cde6dda8ffad30123c","versionType":"git"},{"lessThan":"e4c3ab59021e7c146a84b6671f0d530972bd58b4","status":"affected","version":"980f8710075acaeb226a94cde6dda8ffad30123c","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_color.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"6.8"},{"lessThan":"6.8","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.110","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.51","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.5","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.110","versionStartIncluding":"6.8","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.51","versionStartIncluding":"6.8","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.5","versionStartIncluding":"6.8","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc1","versionStartIncluding":"6.8","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: validate plane degamma LUT size for private color prop\n\nUnlike the CRTC degamma path, which is guarded by\namdgpu_dm_verify_lut_sizes(), the per-plane degamma LUT size was never\nvalidated before use. __set_dm_plane_degamma() passed the user-supplied\nsize straight into __is_lut_linear() and, for a non-linear LUT, into\n__set_input_tf() -> __drm_lut_to_dc_gamma(), the latter always iterating\nMAX_COLOR_LUT_ENTRIES entries regardless of the actual LUT size.\n\nA malformed AMD_PLANE_DEGAMMA_LUT blob (e.g. a single entry) could thus\ntrigger a divide-by-zero in __is_lut_linear() or an out-of-bounds read in\n__drm_lut_to_dc_gamma(). Reject any plane degamma LUT whose size does not\nmatch MAX_COLOR_LUT_ENTRIES, mirroring the invariant the code already\nasserts a few lines below (and which the CRTC path enforces).\n\nThe AMD_PLANE_DEGAMMA_LUT property is only exposed on builds with\nAMD_PRIVATE_COLOR defined."}],"metrics":[{"cvssV3_1":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:L - The bug is reached only through local DRM ioctls (DRM_IOCTL_MODE_CREATEPROPBLOB then DRM_IOCTL_MODE_ATOMIC or MODE_OBJ_SETPROPERTY) on /dev/dri/cardN when setting AMD_PLANE_DEGAMMA_LUT, a private plane property on AMDGPU display; no network or remote-peer path exists into amdgpu_dm color management.\nAC:L - The attacker fully controls the LUT blob size and contents and can deterministically trigger a divide-by-zero with a one-entry blob or a large heap over-read with a short non-linear LUT; no race, memory-layout luck, or victim state is required.\nPR:L - DRM_IOCTL_MODE_ATOMIC requires DRM master, which is the normal state of the logged-in graphical-session user (compositor, gamescope, kiosk, Steam Deck, Android) or the first opener of an unclaimed card; no CAP_SYS_ADMIN or real root is needed.\nUI:N - The attacker creates the undersized blob and issues the atomic commit from their own process; no other user must open a file, plug in a display, or take any action.\nS:U - The divide-by-zero and out-of-bounds read occur in kernel context on the same host inside the amdgpu display driver; impact stays within the kernel security authority with no VM, IOMMU, or sandbox boundary crossed.\nC:H - __drm_lut_to_dc_gamma() always walks MAX_COLOR_LUT_ENTRIES (4096) drm_color_lut records regardless of blob length, over-reading about 32KB of adjacent kernel heap from a short LUT blob and copying those values into dc_gamma and the display pipeline.\nI:H - Kernel heap contents from the over-read are stored into dc_gamma entries and applied by apply_lut_1d() into the plane transfer function that is programmed into DPP degamma hardware, corrupting driver and GPU color-management state with unvalidated memory.\nA:H - A one-entry LUT causes a divide-error (#DE) panic in __is_lut_linear(); a short non-linear LUT makes __drm_lut_to_dc_gamma() walk tens of kilobytes past the blob into potentially unmapped heap, oopsing the kernel on the atomic check/commit path."}]}],"providerMetadata":{"dateUpdated":"2026-09-16T14:39:00.997Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/f6f04d8ae5725bcc893bdc62e3467efd97255c5b"},{"url":"https://git.kernel.org/stable/c/0b2615b8b54f58bbdf986dffb38cbc35214a5cc5"},{"url":"https://git.kernel.org/stable/c/b10cc09b329245c6d95f8fa3e7f068575e3e0e9f"},{"url":"https://git.kernel.org/stable/c/e4c3ab59021e7c146a84b6671f0d530972bd58b4"}],"title":"drm/amd/display: validate plane degamma LUT size for private color prop","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-89819","datePublished":"2026-09-16T10:30:51.898Z","dateReserved":"2026-09-11T19:38:34.768Z","dateUpdated":"2026-09-16T14:39:00.997Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-16 11:16:47","lastModifiedDate":"2026-09-16 15:18:11","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"89819","Ordinal":"1","Title":"drm/amd/display: validate plane degamma LUT size for private col","CVE":"CVE-2026-89819","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"89819","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: validate plane degamma LUT size for private color prop\n\nUnlike the CRTC degamma path, which is guarded by\namdgpu_dm_verify_lut_sizes(), the per-plane degamma LUT size was never\nvalidated before use. __set_dm_plane_degamma() passed the user-supplied\nsize straight into __is_lut_linear() and, for a non-linear LUT, into\n__set_input_tf() -> __drm_lut_to_dc_gamma(), the latter always iterating\nMAX_COLOR_LUT_ENTRIES entries regardless of the actual LUT size.\n\nA malformed AMD_PLANE_DEGAMMA_LUT blob (e.g. a single entry) could thus\ntrigger a divide-by-zero in __is_lut_linear() or an out-of-bounds read in\n__drm_lut_to_dc_gamma(). Reject any plane degamma LUT whose size does not\nmatch MAX_COLOR_LUT_ENTRIES, mirroring the invariant the code already\nasserts a few lines below (and which the CRTC path enforces).\n\nThe AMD_PLANE_DEGAMMA_LUT property is only exposed on builds with\nAMD_PRIVATE_COLOR defined.","Type":"Description","Title":"drm/amd/display: validate plane degamma LUT size for private col"}]}}}