CVE-2026-93183 is a vulnerability in Linux Kernel
Published on September 17, 2026
drm/lima: call drm_mm_init() with a valid allocation range
In the Linux kernel, the following vulnerability has been resolved:
drm/lima: call drm_mm_init() with a valid allocation range
lima_vm_create() is currently run before va_start and va_end are set up,
meaning they are both 0. lima_vm_create() runs drm_mm_init() with them
as arguments for the allocator, and if DRM_DEBUG_MM is enabled the
DRM_MM_BUG_ON check in drm_mm_init then fires, as seen here on
exynos4412-odroid-u2:
[ 1.736297] ------------[ cut here ]------------
[ 1.740370] kernel BUG at drivers/gpu/drm/drm_mm.c:931!
[ 1.745574] Internal error: Oops - BUG: 0 [#1] SMP ARM
[ 1.750697] Modules linked in:
[ 1.753734] CPU: 0 UID: 0 PID: 41 Comm: kworker/u16:1 Not tainted 7.0.10-postmarketos-exynos4 #11 PREEMPT
[ 1.763372] Hardware name: Samsung Exynos (Flattened Device Tree)
[ 1.769446] Workqueue: events_unbound deferred_probe_work_func
[ 1.775261] PC is at drm_mm_init+0x9c/0xa4
[ 1.779339] LR is at lima_vm_create+0x144/0x17c
[ ... ]
Fix the issue by moving the lima_vm_create() call after va_start and
va_end are set up.
Products Associated with CVE-2026-93183
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version a1d2a6339961efc078208dc3b2f006e9e9a8e119 and below af1f276d50c9d7ebcd25770f358ca503a89d96d7 is affected.
- Version a1d2a6339961efc078208dc3b2f006e9e9a8e119 and below fd6bc5f1d6b54047b06b82bab25a7e21e4b1c95a is affected.
- Version a1d2a6339961efc078208dc3b2f006e9e9a8e119 and below ad4e908096dff97646f77b04e2e2825225e215f7 is affected.
- Version a1d2a6339961efc078208dc3b2f006e9e9a8e119 and below 788917ba77f5d69bd368c1d176ecceda346a2951 is affected.
- Version a1d2a6339961efc078208dc3b2f006e9e9a8e119 and below 79a3331ee436c8b1454f897d539606c9b5ebdf9f is affected.
- Version a1d2a6339961efc078208dc3b2f006e9e9a8e119 and below e2a7cee341986cb5b544a8286edc7fb0494c592e is affected.
- Version a1d2a6339961efc078208dc3b2f006e9e9a8e119 and below e0773ad25a34a49aece176721c466cf214e02222 is affected.
- Version a1d2a6339961efc078208dc3b2f006e9e9a8e119 and below 3b3bce4a692ac60d9f4a341e6b597dd1fd0a28f9 is affected.
- Version 5.2 is affected.
- Before 5.2 is unaffected.
- Version 5.10.270, <= 5.10.* is unaffected.
- Version 5.15.221, <= 5.15.* is unaffected.
- Version 6.1.188, <= 6.1.* is unaffected.
- Version 6.6.157, <= 6.6.* is unaffected.
- Version 6.12.110, <= 6.12.* is unaffected.
- Version 6.18.52, <= 6.18.* is unaffected.
- Version 7.2.6, <= 7.2.* is unaffected.
- Version 7.3-rc1, <= * is unaffected.