Answer in brief
CVE-2026-89819 records a Unknown severity vulnerability in drm/amd/display: validate plane degamma LUT size for private color prop. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=980f8710075acaeb226a94cde6dda8ffad30123c <f6f04d8ae5725bcc893bdc62e3467efd97255c5b || >=980f8710075acaeb226a94cde6dda8ffad30123c <0b2615b8b54f58bbdf986dffb38cbc35214a5cc5 || >=980f8710075acaeb226a94cde6dda8ffad30123c <b10cc09b329245c6d95f8fa3e7f068575e3e0e9f || >=980f8710075acaeb226a94cde6dda8ffad30123c <e4c3ab59021e7c146a84b6671f0d530972bd58b4 | f6f04d8ae5725bcc893bdc62e3467efd97255c5b, 0b2615b8b54f58bbdf986dffb38cbc35214a5cc5, b10cc09b329245c6d95f8fa3e7f068575e3e0e9f, e4c3ab59021e7c146a84b6671f0d530972bd58b4 |
| Linux/Linuxgeneric | 6.8 | Not reported |
Published upstream
Sep 16, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 16, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 16, 2026
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: validate plane degamma LUT size for private color prop Unlike the CRTC degamma path, which is guarded by amdgpu_dm_verify_lut_sizes(), the per-plane degamma LUT size was never validated before use. __set_dm_plane_degamma() passed the user-supplied size straight into __is_lut_linear() and, for a non-linear LUT, into __set_input_tf() -> __drm_lut_to_dc_gamma(), the latter always iterating MAX_COLOR_LUT_ENTRIES entries regardless of the actual LUT size. A malformed AMD_PLANE_DEGAMMA_LUT blob (e.g. a single entry) could thus trigger a divide-by-zero in __is_lut_linear() or an out-of-bounds read in __drm_lut_to_dc_gamma(). Reject any plane degamma LUT whose size does not match MAX_COLOR_LUT_ENTRIES, mirroring the invariant the code already asserts a few lines below (and which the CRTC path enforces). The AMD_PLANE_DEGAMMA_LUT property is only exposed on builds with AMD_PRIVATE_COLOR defined.
Quoted source text, attributed separately from HOL analysis.