PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-93177 Linux CVE debrief

A bounds-checking vulnerability was resolved in the Linux kernel's drm/amdgpu/pm/powerplay for Vega10 lookup, affecting voltage index handling. This vulnerability could lead to system instability if exploited. Linux kernel administrators and developers, particularly those using Vega10-based systems, should verify and apply kernel updates to prevent potential system instability. The vulnerability has been resolved with the addition of -EINVAL returns for out-of-range indices. The CVE record and NVD entry provide details on the vulnerability.

Vendor
Linux
Product
Unknown
CVSS
HIGH 7.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-17
Original CVE updated
2026-09-18
Advisory published
2026-09-17
Advisory updated
2026-09-18

Who should care

Linux kernel administrators and developers, particularly those using Vega10-based systems, should verify and apply kernel updates to prevent potential system instability. System operators and security teams responsible for managing Linux kernel deployments should also be aware of this vulnerability and take necessary precautions. This includes reviewing system configurations, monitoring system stability, and verifying kernel versions.

Why it matters

CVE-2026-93177 is a bounds-checking vulnerability in the Linux kernel's drm/amdgpu/pm/powerplay for Vega10 lookup. Linux kernel administrators and developers, particularly those using Vega10-based systems, should verify and apply kernel updates to prevent potential system instability.

  • Verify kernel version and apply updates to prevent system instability
  • Monitor system stability and voltage index handling to detect potential issues
  • Review system configurations to identify potential exposure

Technical summary

The Linux kernel's drm/amdgpu/pm/powerplay has a bounds-checking vulnerability in Vega10 lookup, affecting voltage index handling. The vulnerability has been resolved with the addition of -EINVAL returns for out-of-range indices. This change prevents potential system instability by ensuring that voltage indices are within valid ranges. Linux kernel administrators and developers, particularly those using Vega10-based systems, should verify and apply kernel updates to prevent potential system instability. The vulnerability could lead to system instability if exploited.

Defensive priority

Verify and apply kernel updates; monitor system stability

Recommended defensive actions

  • Verify kernel version and apply updates if necessary
  • Monitor system stability and voltage index handling
  • Review system configurations for potential exposure
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability. However, specific exploitation details and affected systems require further verification. The vulnerability has been resolved with the addition of -EINVAL returns for out-of-range indices. Linux kernel administrators and developers should verify kernel version and apply updates if necessary to prevent potential system instability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-93177 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-93177

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-93177 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-93177

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/06aef6dcc1d52da5112cbcde39c062e493247ab5

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/206e478810d6af50b25d8da72e3af8d55a014365

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/25dedc13ceb9b6109c79c92a726ca4ca017c9eaa

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/46d27e56dbd6345b9c7b62b67ec57407bf3bf29a

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/6fa33f594e46e775a94097f71b486d7b006b6917

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/ae25c92d91f2cb90ede2b0eb0f58efa82ccc718b

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/b349dcf061a6dc8c6cef9a10530331ef2ff66c72

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/dfe89f1a0c7f40ef858b93881198f9728df956cf

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.