CVE-2026-90289
Linux · Kernel
A buffer size mismatch in the AMDGPU display driver allows local authenticated users to potentially trigger memory corruption, impacting system stability and security.
Executive summary
A vulnerability in the Linux kernel AMDGPU display driver could allow a local attacker with low privileges to achieve high-impact system compromise.
Vulnerability
The vulnerability is caused by an off-by-one error in the AMDGPU display driver when handling Multi-Stream Transport (MST) HDCP connectors. An authenticated local attacker can leverage this array size mismatch to potentially cause memory corruption or other undefined behavior within the kernel.
Business impact
The CVSS score of 7.8 (High) reflects the potential for a local attacker to escalate privileges or cause a system crash. Successful exploitation could lead to full system compromise, unauthorized data access, or denial of service, which would significantly disrupt business operations and compromise the integrity of the underlying host.
Remediation
Immediate Action: Update the Linux kernel to version 5.16, 6.2, or 7.2.6 or later to incorporate the required array size adjustments.
Proactive Monitoring: Monitor system logs for kernel panics or unusual AMDGPU driver behavior that may indicate exploitation attempts.
Compensating Controls: Restrict local access to the affected hardware systems to prevent unauthorized users from executing code that interacts with the graphics subsystem.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the High severity rating and the potential for kernel-level impact, administrators should prioritize patching the Linux kernel across all affected environments. While this requires local access, the criticality of the kernel makes it a high-value target for privilege escalation efforts. Apply the recommended kernel updates as part of the next scheduled maintenance window.
More Linux CVEs all →
History
CVE Brief tracked this CVE 2 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 7.8 (3.1)
- Analyst report written