CVE-2026-90289: Linux
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Resize MST HDCP per-connector arrays to 32 AMDGPU_DM_MAX_DISPLAY_INDEX is 31. It suggest a maximum number of 32 connectors. But the way it's used is like MAX_DISPLAY_COUNT. Hence we're off by one with DRM core, which supports a max of 32 connectors. Rename AMDGPU_DM_MAX_DISPLAY_INDEX to AMDGPU_DM_MAX_DISPLAY_COUNT to match its actual use, and increase the size to 32 to match the originally intended size.
Affected products
- Linux Linux: from 5.15.128, before 5.16 (fixed in 5.16); from 6.1.47, before 6.2 (fixed in 6.2); from 6.3, before 7.2.6 (fixed in 7.2.6)
Published 2026-09-17. Last modified 2026-09-18.