CVE-2026-93183
Last modified
CVE-2026-93183 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: drm/lima: call drm_mm_init() with a valid allocation range lima_vm_create() is currently run before va_start and va_end are set up, meaning they are both 0. lima_vm_create() runs drm_mm_init() with them as arguments for the allocator, and if DRM_DEBUG_MM is enabled the DRM_MM_BUG_ON check in drm_mm_init then fires, as seen here on exynos4412-odroid-u2: [ 1.736297] ------------[ cut here ]------------ [ 1.740370] kernel BUG at drivers/gpu/drm/drm_mm.c:931! [ 1.745574] Internal error: Oops - BUG: 0 [#1] SMP ARM [ 1.750697] Modules linked in: [ 1.753734] CPU: 0 UID: 0 PID: 41 Comm: kworker/u16:1 Not tainted 7.0.10-postmarketos-exynos4 #11 PREEMPT [ 1.763372] Hardware name: Samsung Exynos (Flattened Device Tree) [ 1.769446] Workqueue: events_unbound deferred_probe_work_func [ 1.775261] PC is at drm_mm_init+0x9c/0xa4 [ 1.779339] LR is at lima_vm_create+0x144/0x17c [ ...
Description
In the Linux kernel, the following vulnerability has been resolved: drm/lima: call drm_mm_init() with a valid allocation range lima_vm_create() is currently run before va_start and va_end are set up, meaning they are both 0. lima_vm_create() runs drm_mm_init() with them as arguments for the allocator, and if DRM_DEBUG_MM is enabled the DRM_MM_BUG_ON check in drm_mm_init then fires, as seen here on exynos4412-odroid-u2: [ 1.736297] ------------[ cut here ]------------ [ 1.740370] kernel BUG at drivers/gpu/drm/drm_mm.c:931! [ 1.745574] Internal error: Oops - BUG: 0 [#1] SMP ARM [ 1.750697] Modules linked in: [ 1.753734] CPU: 0 UID: 0 PID: 41 Comm: kworker/u16:1 Not tainted 7.0.10-postmarketos-exynos4 #11 PREEMPT [ 1.763372] Hardware name: Samsung Exynos (Flattened Device Tree) [ 1.769446] Workqueue: events_unbound deferred_probe_work_func [ 1.775261] PC is at drm_mm_init+0x9c/0xa4 [ 1.779339] LR is at lima_vm_create+0x144/0x17c [ ... ] Fix the issue by moving the lima_vm_create() call after va_start and va_end are set up.
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= a1d2a6339961efc078208dc3b2f006e9e9a8e119, < af1f276d50c9d7ebcd25770f358ca503a89d96d7; >= a1d2a6339961efc078208dc3b2f006e9e9a8e119, < fd6bc5f1d6b54047b06b82bab25a7e21e4b1c95a; >= a1d2a6339961efc078208dc3b2f006e9e9a8e119, < ad4e908096dff97646f77b04e2e2825225e215f7; >= a1d2a6339961efc078208dc3b2f006e9e9a8e119, < 788917ba77f5d69bd368c1d176ecceda346a2951; >= a1d2a6339961efc078208dc3b2f006e9e9a8e119, < 79a3331ee436c8b1454f897d539606c9b5ebdf9f; >= a1d2a6339961efc078208dc3b2f006e9e9a8e119, < e2a7cee341986cb5b544a8286edc7fb0494c592e; >= a1d2a6339961efc078208dc3b2f006e9e9a8e119, < e0773ad25a34a49aece176721c466cf214e02222; >= a1d2a6339961efc078208dc3b2f006e9e9a8e119, < 3b3bce4a692ac60d9f4a341e6b597dd1fd0a28f9 |
| Linux | Linux | 5.2 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-93183?
How severe is CVE-2026-93183?
How do I fix CVE-2026-93183?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-93178In the Linux kernel, the following vulnerability has been re…7.1
- CVE-2026-93179In the Linux kernel, the following vulnerability has been re…
- CVE-2026-9318tablib prior to 3.10.0 contains a stored cross-site scriptin…5.4
- CVE-2026-93180In the Linux kernel, the following vulnerability has been re…
- CVE-2026-93181In the Linux kernel, the following vulnerability has been re…
- CVE-2026-93182In the Linux kernel, the following vulnerability has been re…
- CVE-2026-93184In the Linux kernel, the following vulnerability has been re…
- CVE-2026-93185In the Linux kernel, the following vulnerability has been re…
- CVE-2026-93186In the Linux kernel, the following vulnerability has been re…
- CVE-2026-93187In the Linux kernel, the following vulnerability has been re…
- CVE-2026-93188In the Linux kernel, the following vulnerability has been re…
- CVE-2026-93189In the Linux kernel, the following vulnerability has been re…8.8
Are you affected by CVE-2026-93183?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
