Junglewise Threat Intelligence

CVE-2026-93068: Linux kernel AMD display manager I2C teardown race condition

CVE-2026-93068 · Severity: info · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's AMD display driver has a race condition during device removal that can cause the system to crash. When the display hardware is being shut down, I2C adapters (used for communication with display-connected devices) may still be accessible to user applications. If an I2C operation occurs after internal display state has been torn down, the kernel crashes with a NULL pointer dereference. This affects systems with AMD graphics during device removal or driver unload.

Technical details

This is a race condition (CWE-362) in the AMD display manager's I2C adapter teardown sequence in the Linux kernel's DRM subsystem. The vulnerable component is the amdgpu_dm_i2c_xfer() function in drivers/gpu/drm/amd/display/amdgpu_dm/. The vulnerability occurs because I2C adapters remain visible to userspace via the i2c-dev interface while DM (display manager) teardown is in progress. A concurrent i2c-dev transfer initiated via ioctl can enter amdgpu_dm_i2c_xfer() after backing DM structures have been freed, causing a NULL pointer dereference. The fix uses devres groups to ensure I2C adapters are removed and in-flight transfers drain before DM state is torn down during dm_hw_fini(). No authentication is required; local unprivileged users can trigger this via /dev/i2c-* device access. The patch is available and has been merged into Linux stable.

Affected products

  • Linux Linux kernel versions prior to fix commit e4ae30a12aa95942814957d8bc1ce7366a7107d7

Timeline

  • 2026-09-17: disclosed
  • 2026-06-29: patched: Patch authored by Geoffrey McRae

References

Related threats