Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-89773
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2026-89773 is a vulnerability in the Linux kernel's AMD Display (drm/amd/display) subsystem where the HDCP configuration routine is incorrectly invoked during display stream transition states that lack a valid dm_stream_ctx. This use of an uninitialized resource (CWE-908) can lead to undefined behavior when the HDCP routine proceeds without a valid stream context. The vulnerability was published on September 11, 2026, and affects Linux kernel versions prior to the fix commits f733276ae737 and d5164580a994, with patched versions available in kernel 7.2.4 and 7.3-rc1. The CVSS category is estimated as Medium, with an EPSS score of 0.0 (GitHub Advisory, Red Hat Bugzilla).

Technical details

The root cause is classified as CWE-908 (Use of Uninitialized Resource): during display stream transition states in the AMD Display driver, the HDCP configuration routine (dm_stream_ctx) is accessed before a valid stream context has been established. The fix skips the HDCP configuration update when the driver is in a transition state, ensuring the routine only executes when a valid stream is created. This is a local, kernel-level flaw within the drm/amd/display driver component, requiring the system to be using AMD GPU hardware with HDCP-capable display outputs. Patch commits f733276ae737e4d599d1e19de6722aee1521a154 and d5164580a99477dcfe15cea101b153b1e63f1535 address the issue in the stable kernel tree (GitHub Advisory).

Impact

Exploitation of this vulnerability could allow invalid stream contexts to bypass HDCP (High-bandwidth Digital Content Protection) protections on DisplayPort or HDMI outputs, potentially exposing protected content to interception. In addition, accessing an uninitialized dm_stream_ctx may cause kernel instability or crashes (denial of service) on systems with AMD GPUs. The impact is primarily limited to systems running affected Linux kernel versions with AMD display hardware; there is no known path for remote exploitation or lateral movement (Red Hat Bugzilla, GitHub Advisory).

Exploitability

There are no known public proof-of-concept exploits, exploit kits, or reports of in-the-wild exploitation for CVE-2026-89773. The EPSS score is 0.0, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation would require local access to a system with an AMD GPU and the ability to trigger display stream transitions (GitHub Advisory).

Mitigation and workarounds

The vulnerability is patched in Linux kernel version 7.2.4 and 7.3-rc1. Users should update to kernel 7.2.4 or later, or apply the specific fix commits f733276ae737e4d599d1e19de6722aee1521a154 and d5164580a99477dcfe15cea101b153b1e63f1535 from the stable kernel tree. No configuration-based workarounds have been published; upgrading the kernel is the recommended remediation. Red Hat has tracked this issue and users of affected Red Hat-based distributions should monitor for updated kernel packages (GitHub Advisory, Red Hat Bugzilla).

Community reactions

The vulnerability received routine coverage in CVE aggregation feeds and was briefly mentioned in a Reddit CVE daily brief on September 12, 2026. No notable researcher commentary, vendor statements beyond the kernel fix, or significant media coverage has been identified for this vulnerability (Red Hat Bugzilla).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

linux

Fixed

sid

linux

Fixed

trixie

linux

Fixed

Ubuntu

Affected

bionic (esm-infra)

linux

Affected

bionic (fips-updates)

linux-fips

Affected

bionic (fips)

linux-fips

Affected

devel

linux: 7.3.0-5.5

Affected

focal (esm-infra)

linux

Affected

focal (fips-updates)

linux-fips

Affected

focal (fips)

linux-fips

Affected

jammy

linux

Affected

SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-93189HIGH8.8
  • Linux Kernel logoLinux Kernel
  • linux-nvidia-7.0
NoYesSep 17, 2026
CVE-2026-93188NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-fips
NoYesSep 17, 2026
CVE-2026-93182NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-intel-iotg
NoYesSep 17, 2026
CVE-2026-93181NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-nvidia
NoNoSep 17, 2026
CVE-2026-93174NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoYesSep 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management