Executive brief
A vulnerability was identified in the Linux kernel's AMD display driver where certain hardware encoder settings could be accessed incorrectly. This could allow a local attacker to cause a system crash or potentially access restricted memory by triggering an out-of-bounds operation during display configuration. The issue affects systems using specific AMD graphics hardware and has been resolved in recent kernel updates.
Technical details
An out-of-bounds read/write vulnerability exists in the AMD display driver (drm/amd/display) within the resource management components for various DCN (Display Core Next) versions. The root cause is insufficient validation of the 'eng_id' parameter in the 'stream_encoder_create' function family (e.g., dcn35_stream_encoder_create). Specifically, the code used a less-than-or-equal-to check against ENGINE_ID_DIGF (value 5) for an array (stream_enc_regs) that only contains 5 elements (indices 0-4). Additionally, the 'eng_id' variable, being a signed type, could theoretically be negative. An attacker with the ability to influence display resource allocation could trigger an out-of-bounds access. The fix implements explicit bounds checking using ARRAY_SIZE() and ensures negative values are rejected.
Affected products
- Linux Linux Kernel DCN351, DCN35, DCN321, DCN32, DCN316, DCN315 resource drivers
Timeline
- 2026-02-06: patched: Initial patch authored by Srinivasan Shanmugam
- 2026-06-03: disclosed: CVE-2026-46263 published