
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-89773 is a vulnerability in the Linux kernel's AMD Display (drm/amd/display) subsystem where the HDCP configuration routine is incorrectly invoked during display stream transition states that lack a valid dm_stream_ctx. This use of an uninitialized resource (CWE-908) can lead to undefined behavior when the HDCP routine proceeds without a valid stream context. The vulnerability was published on September 11, 2026, and affects Linux kernel versions prior to the fix commits f733276ae737 and d5164580a994, with patched versions available in kernel 7.2.4 and 7.3-rc1. The CVSS category is estimated as Medium, with an EPSS score of 0.0 (GitHub Advisory, Red Hat Bugzilla).
The root cause is classified as CWE-908 (Use of Uninitialized Resource): during display stream transition states in the AMD Display driver, the HDCP configuration routine (dm_stream_ctx) is accessed before a valid stream context has been established. The fix skips the HDCP configuration update when the driver is in a transition state, ensuring the routine only executes when a valid stream is created. This is a local, kernel-level flaw within the drm/amd/display driver component, requiring the system to be using AMD GPU hardware with HDCP-capable display outputs. Patch commits f733276ae737e4d599d1e19de6722aee1521a154 and d5164580a99477dcfe15cea101b153b1e63f1535 address the issue in the stable kernel tree (GitHub Advisory).
Exploitation of this vulnerability could allow invalid stream contexts to bypass HDCP (High-bandwidth Digital Content Protection) protections on DisplayPort or HDMI outputs, potentially exposing protected content to interception. In addition, accessing an uninitialized dm_stream_ctx may cause kernel instability or crashes (denial of service) on systems with AMD GPUs. The impact is primarily limited to systems running affected Linux kernel versions with AMD display hardware; there is no known path for remote exploitation or lateral movement (Red Hat Bugzilla, GitHub Advisory).
There are no known public proof-of-concept exploits, exploit kits, or reports of in-the-wild exploitation for CVE-2026-89773. The EPSS score is 0.0, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation would require local access to a system with an AMD GPU and the ability to trigger display stream transitions (GitHub Advisory).
The vulnerability is patched in Linux kernel version 7.2.4 and 7.3-rc1. Users should update to kernel 7.2.4 or later, or apply the specific fix commits f733276ae737e4d599d1e19de6722aee1521a154 and d5164580a99477dcfe15cea101b153b1e63f1535 from the stable kernel tree. No configuration-based workarounds have been published; upgrading the kernel is the recommended remediation. Red Hat has tracked this issue and users of affected Red Hat-based distributions should monitor for updated kernel packages (GitHub Advisory, Red Hat Bugzilla).
The vulnerability received routine coverage in CVE aggregation feeds and was briefly mentioned in a Reddit CVE daily brief on September 12, 2026. No notable researcher commentary, vendor statements beyond the kernel fix, or significant media coverage has been identified for this vulnerability (Red Hat Bugzilla).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."