---
id: CVE-2026-93183
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  drm/lima: call drm_mm_init() with a valid allocation range

  lima_vm_create() is currently run before va_start and va_end are set up,
  meaning they are both 0
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  drm/lima: call drm_mm_init() with a valid allocation range

  lima_vm_create() is currently run before va_start and va_end are set up,
  meaning they are both 0. lima_vm_cr…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= a1d2a6339961efc078208dc3b2f006e9e9a8e119 <
    af1f276d50c9d7ebcd25770f358ca503a89d96d7
  - >-
    Linux >= a1d2a6339961efc078208dc3b2f006e9e9a8e119 <
    fd6bc5f1d6b54047b06b82bab25a7e21e4b1c95a
  - >-
    Linux >= a1d2a6339961efc078208dc3b2f006e9e9a8e119 <
    ad4e908096dff97646f77b04e2e2825225e215f7
  - >-
    Linux >= a1d2a6339961efc078208dc3b2f006e9e9a8e119 <
    788917ba77f5d69bd368c1d176ecceda346a2951
  - >-
    Linux >= a1d2a6339961efc078208dc3b2f006e9e9a8e119 <
    79a3331ee436c8b1454f897d539606c9b5ebdf9f
  - >-
    Linux >= a1d2a6339961efc078208dc3b2f006e9e9a8e119 <
    e2a7cee341986cb5b544a8286edc7fb0494c592e
  - >-
    Linux >= a1d2a6339961efc078208dc3b2f006e9e9a8e119 <
    e0773ad25a34a49aece176721c466cf214e02222
  - >-
    Linux >= a1d2a6339961efc078208dc3b2f006e9e9a8e119 <
    3b3bce4a692ac60d9f4a341e6b597dd1fd0a28f9
  - Linux 5.2
published: '2026-09-17'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T17:18:14.290'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-93183'
references:
  - url: 'https://git.kernel.org/stable/c/3b3bce4a692ac60d9f4a341e6b597dd1fd0a28f9'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/788917ba77f5d69bd368c1d176ecceda346a2951'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/79a3331ee436c8b1454f897d539606c9b5ebdf9f'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/ad4e908096dff97646f77b04e2e2825225e215f7'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/af1f276d50c9d7ebcd25770f358ca503a89d96d7'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/e0773ad25a34a49aece176721c466cf214e02222'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/e2a7cee341986cb5b544a8286edc7fb0494c592e'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/fd6bc5f1d6b54047b06b82bab25a7e21e4b1c95a'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-17T16:21:47.727Z'
epss: 0.00211
epssPercentile: 0.10106
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

drm/lima: call drm_mm_init() with a valid allocation range

lima_vm_create() is currently run before va_start and va_end are set up,
meaning they are both 0. lima_vm_create() runs drm_mm_init() with them
as arguments for the allocator, and if DRM_DEBUG_MM is enabled the
DRM_MM_BUG_ON check in drm_mm_init then fires, as seen here on
exynos4412-odroid-u2:

[    1.736297] ------------[ cut here ]------------
[    1.740370] kernel BUG at drivers/gpu/drm/drm_mm.c:931!
[    1.745574] Internal error: Oops - BUG: 0 [#1] SMP ARM
[    1.750697] Modules linked in:
[    1.753734] CPU: 0 UID: 0 PID: 41 Comm: kworker/u16:1 Not tainted 7.0.10-postmarketos-exynos4 #11 PREEMPT
[    1.763372] Hardware name: Samsung Exynos (Flattened Device Tree)
[    1.769446] Workqueue: events_unbound deferred_probe_work_func
[    1.775261] PC is at drm_mm_init+0x9c/0xa4
[    1.779339] LR is at lima_vm_create+0x144/0x17c
[ ... ]

Fix the issue by moving the lima_vm_create() call after va_start and
va_end are set up.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
