CVE-2026-90289
Received
Received - Intake
BaseFortify
Vulnerability report for CVE-2026-90289, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-17
Last updated on: 2026-09-18
Assigner: kernel.org
Description
Description
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Resize MST HDCP per-connector arrays to 32
AMDGPU_DM_MAX_DISPLAY_INDEX is 31. It suggest a maximum number of
32 connectors. But the way it's used is like MAX_DISPLAY_COUNT.
Hence we're off by one with DRM core, which supports a max of 32
connectors.
Rename AMDGPU_DM_MAX_DISPLAY_INDEX to AMDGPU_DM_MAX_DISPLAY_COUNT
to match its actual use, and increase the size to 32 to match the
originally intended size.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Linux | Linux | 82986fd631fa04bcedaefe11a6b3767601cbe84f |
| Linux | Linux | 82986fd631fa04bcedaefe11a6b3767601cbe84f |
| Linux | Linux | 99c444d3c3c43db354b253d9bfac081073dcb484 |
| Linux | Linux | d90f97cb3821c47bdf773dcf6cade143773ec764 |
| Linux | Linux | 5.15.128 |
| Linux | Linux | 6.1.47 |
| Linux | Linux | 6.3 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |