Linux Kernel DCN401 Link Access Vulnerability Causes Crash

Vulnerability

A vulnerability in the Linux kernel's handling of DisplayPort links in the AMD DCN401 display controller can lead to a system crash. This issue arises because the current implementation does not properly check the signal type before accessing the link encoder on a DisplayPort internal audio (dpia) link. The vulnerability is present in the Linux kernel stable tree.

Impact

Failing to check the signal type can cause a crash when accessing the link encoder on a dpia link.

Reproduction

The vulnerability can be reproduced by accessing the link encoder on a DisplayPort internal audio link without the proper signal type check. This can be done by manipulating the stream calculation process in the DCN401 hardware sequence file of the AMD display driver.

Remediation

Users can upgrade to the latest version of the Linux kernel where this vulnerability has been addressed.

Added: May 6, 2026, 1:05 PM
Updated: May 6, 2026, 1:05 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
3.9
remediation
7.7
relevance
7.6
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.