{"id":"CVE-2026-89819","summary":"drm/amd/display: validate plane degamma LUT size for private color prop","details":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: validate plane degamma LUT size for private color prop\n\nUnlike the CRTC degamma path, which is guarded by\namdgpu_dm_verify_lut_sizes(), the per-plane degamma LUT size was never\nvalidated before use. __set_dm_plane_degamma() passed the user-supplied\nsize straight into __is_lut_linear() and, for a non-linear LUT, into\n__set_input_tf() -\u003e __drm_lut_to_dc_gamma(), the latter always iterating\nMAX_COLOR_LUT_ENTRIES entries regardless of the actual LUT size.\n\nA malformed AMD_PLANE_DEGAMMA_LUT blob (e.g. a single entry) could thus\ntrigger a divide-by-zero in __is_lut_linear() or an out-of-bounds read in\n__drm_lut_to_dc_gamma(). Reject any plane degamma LUT whose size does not\nmatch MAX_COLOR_LUT_ENTRIES, mirroring the invariant the code already\nasserts a few lines below (and which the CRTC path enforces).\n\nThe AMD_PLANE_DEGAMMA_LUT property is only exposed on builds with\nAMD_PRIVATE_COLOR defined.","modified":"2026-09-18T03:48:33.062806237Z","published":"2026-09-16T10:30:51.898Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89819.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/0b2615b8b54f58bbdf986dffb38cbc35214a5cc5"},{"type":"WEB","url":"https://git.kernel.org/stable/c/b10cc09b329245c6d95f8fa3e7f068575e3e0e9f"},{"type":"WEB","url":"https://git.kernel.org/stable/c/e4c3ab59021e7c146a84b6671f0d530972bd58b4"},{"type":"WEB","url":"https://git.kernel.org/stable/c/f6f04d8ae5725bcc893bdc62e3467efd97255c5b"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89819.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89819"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"980f8710075acaeb226a94cde6dda8ffad30123c"},{"fixed":"f6f04d8ae5725bcc893bdc62e3467efd97255c5b"},{"fixed":"0b2615b8b54f58bbdf986dffb38cbc35214a5cc5"},{"fixed":"b10cc09b329245c6d95f8fa3e7f068575e3e0e9f"},{"fixed":"e4c3ab59021e7c146a84b6671f0d530972bd58b4"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89819.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.8.0"},{"fixed":"6.12.110"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.51"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.2.5"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89819.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}