๐Ÿ” CVE Alert

CVE-2026-80576

UNKNOWN 0.0

drm/amdgpu: reject oversized IBs with per-ring packet limits

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: reject oversized IBs with per-ring packet limits On GFX rings, amdgpu_cs_p2_ib() passed user-supplied ib_bytes through to ib->length_dw without a limit, while ring_emit_ib() encodes length into packet fields. Oversized values can corrupt adjacent control bits and destabilize command submission. Add a per-ring IB packet size limit helper and reject command submissions exceeding the corresponding dword limit before IB allocation. Use the documented 20-bit limit for GFX/compute/SDMA/VPE, and apply the MM fallback limit for other ring types. (cherry picked from commit 7f48fa2cf62e3fa6c9c3870aa74988f773247e52)

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 26, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 6e164ba1057175fb8a370d8e05cbff5c57eac0c8 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 1474f3970d1afd303e12ff14d06808eabb371576 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 07fe270ec07c138a70afe7a81e115a85c35c545c 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < fd37f9dd5b5ab70a46fa7bc76623c0528d602b27 0 < 6.12.105 0 < 6.18.46 0 < 7.1.10
Linux / Linux
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/6e164ba1057175fb8a370d8e05cbff5c57eac0c8 git.kernel.org: https://git.kernel.org/stable/c/1474f3970d1afd303e12ff14d06808eabb371576 git.kernel.org: https://git.kernel.org/stable/c/07fe270ec07c138a70afe7a81e115a85c35c545c git.kernel.org: https://git.kernel.org/stable/c/fd37f9dd5b5ab70a46fa7bc76623c0528d602b27