{"api_version":"1","generated_at":"2026-09-28T15:30:59+00:00","cve":"CVE-2026-93176","urls":{"html":"https://cve.report/CVE-2026-93176","api":"https://cve.report/api/cve/CVE-2026-93176.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-93176","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-93176"},"summary":{"title":"drm/amd/display: Fix dangling pointer in plane reset function","description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix dangling pointer in plane reset function\n\namdgpu_dm_plane_drm_plane_reset() frees the old state before allocating\na new one. If kzalloc() fails, the function returns without updating\nthe state pointer, leaving a dangling pointer to already freed memory.\n\nFix this by allocating the new state first. On allocation failure, the\nold state remains untouched and the function safely returns.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.\n\n[adjust for movement around current amd-staging-drm-next]","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-17 17:18:13","updated_at":"2026-09-18 18:18:23"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"7","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"7","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"baseScore":7,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/80c0f51aced43d6eaf72f95a2833b0a77cf7880d","name":"https://git.kernel.org/stable/c/80c0f51aced43d6eaf72f95a2833b0a77cf7880d","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/98cad4bd1443975d972f4c7f705980da03722a22","name":"https://git.kernel.org/stable/c/98cad4bd1443975d972f4c7f705980da03722a22","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-93176","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93176","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5d945cbcd4b16a29d6470a80dfb19738f9a4319f 80c0f51aced43d6eaf72f95a2833b0a77cf7880d git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5d945cbcd4b16a29d6470a80dfb19738f9a4319f 98cad4bd1443975d972f4c7f705980da03722a22 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.0","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.0 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.6 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"93176","cve":"CVE-2026-93176","epss":"0.001320000","percentile":"0.031380000","score_date":"2026-09-21","updated_at":"2026-09-22 00:03:18"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_plane.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"80c0f51aced43d6eaf72f95a2833b0a77cf7880d","status":"affected","version":"5d945cbcd4b16a29d6470a80dfb19738f9a4319f","versionType":"git"},{"lessThan":"98cad4bd1443975d972f4c7f705980da03722a22","status":"affected","version":"5d945cbcd4b16a29d6470a80dfb19738f9a4319f","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_plane.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"6.0"},{"lessThan":"6.0","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.6","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.6","versionStartIncluding":"6.0","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc1","versionStartIncluding":"6.0","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix dangling pointer in plane reset function\n\namdgpu_dm_plane_drm_plane_reset() frees the old state before allocating\na new one. If kzalloc() fails, the function returns without updating\nthe state pointer, leaving a dangling pointer to already freed memory.\n\nFix this by allocating the new state first. On allocation failure, the\nold state remains untouched and the function safely returns.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.\n\n[adjust for movement around current amd-staging-drm-next]"}],"metrics":[{"cvssV3_1":{"baseScore":7,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:L - The UAF is in amdgpu_dm_plane_drm_plane_reset() after plane->state is already live, reached from drm_mode_config_reset() in drm_atomic_helper_resume() via dm_destroy_cached_state() in dm_resume(). Callers are local: amdgpu_pmops_resume (S3/S0ix) and amdgpu_drm_ioctl then pm_runtime_get_sync then amdgpu_pmops_runtime_resume. No network protocol message is involved.\nAC:H - The dangling plane->state exists only when kzalloc of struct dm_plane_state fails after amdgpu_dm_plane_drm_plane_destroy_state() has already kfree'd the previous state. That GFP_KERNEL miss during dm_resume()/drm_mode_config_reset() is not reliably attacker-controlled.\nPR:L - amdgpu_drm_ioctl() issues pm_runtime_get_sync() with no capable() check, so any local user who can open /dev/dri/renderD* or card* (typical video/render-group access) can runtime-resume into dm_resume() and drm_mode_config_reset(). This is not init-namespace root.\nUI:N - The attacker opens the DRM node and issues their own ioctl to drive amdgpu_pmops_runtime_resume() into dm_resume(), or initiates their own session suspend/resume; no separate victim must mount media, attach a display, or accept a prompt.\nS:U - The freed object is the host-kernel struct dm_plane_state stored in drm_plane.state by amdgpu_dm; the UAF stays in the same kernel security authority and is not a KVM/Xen, IOMMU, or sandbox escape.\nC:H - After the kfree, drm_atomic_helper_commit_duplicated_state() stores the dangling plane->state as old_state and amdgpu_dm_plane_drm_plane_duplicate_state() uses to_dm_plane_state(plane->state) to read dc_state and degamma/ctm/lut blobs from the freed heap object.\nI:H - drm_atomic_helper_swap_state() later calls atomic_destroy_state() on that already-freed plane->state (double-free), and duplicate_state copies reclaimed dc_state/fb pointers into the new live dm_plane_state, enabling a kernel write and control-flow hijack.\nA:H - drm_atomic_helper_resume() uses the freed plane->state immediately in drm_atomic_helper_commit_duplicated_state(), and DRM_IOCTL_MODE_GETPLANE loads plane->state->crtc/fb; either path oopses or panics the host."}]}],"providerMetadata":{"dateUpdated":"2026-09-18T17:56:22.149Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/80c0f51aced43d6eaf72f95a2833b0a77cf7880d"},{"url":"https://git.kernel.org/stable/c/98cad4bd1443975d972f4c7f705980da03722a22"}],"title":"drm/amd/display: Fix dangling pointer in plane reset function","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-93176","datePublished":"2026-09-17T16:12:05.278Z","dateReserved":"2026-09-17T16:02:15.090Z","dateUpdated":"2026-09-18T17:56:22.149Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-17 17:18:13","lastModifiedDate":"2026-09-18 18:18:23","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1,"impactScore":5.9}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"93176","Ordinal":"1","Title":"drm/amd/display: Fix dangling pointer in plane reset function","CVE":"CVE-2026-93176","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"93176","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix dangling pointer in plane reset function\n\namdgpu_dm_plane_drm_plane_reset() frees the old state before allocating\na new one. If kzalloc() fails, the function returns without updating\nthe state pointer, leaving a dangling pointer to already freed memory.\n\nFix this by allocating the new state first. On allocation failure, the\nold state remains untouched and the function safely returns.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.\n\n[adjust for movement around current amd-staging-drm-next]","Type":"Description","Title":"drm/amd/display: Fix dangling pointer in plane reset function"}]}}}