๐Ÿ” CVE Alert

CVE-2026-80576

HIGH 8.8

drm/amdgpu: reject oversized IBs with per-ring packet limits

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: reject oversized IBs with per-ring packet limits On GFX rings, amdgpu_cs_p2_ib() passed user-supplied ib_bytes through to ib->length_dw without a limit, while ring_emit_ib() encodes length into packet fields. Oversized values can corrupt adjacent control bits and destabilize command submission. Add a per-ring IB packet size limit helper and reject command submissions exceeding the corresponding dword limit before IB allocation. Use the documented 20-bit limit for GFX/compute/SDMA/VPE, and apply the MM fallback limit for other ring types. (cherry picked from commit 7f48fa2cf62e3fa6c9c3870aa74988f773247e52)

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 26, 2026
Last Updated Aug 27, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new high vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
d38ceaf99ed015f2a0b9af3499791bd3a3daae21 < 6e164ba1057175fb8a370d8e05cbff5c57eac0c8 d38ceaf99ed015f2a0b9af3499791bd3a3daae21 < 1474f3970d1afd303e12ff14d06808eabb371576 d38ceaf99ed015f2a0b9af3499791bd3a3daae21 < 07fe270ec07c138a70afe7a81e115a85c35c545c d38ceaf99ed015f2a0b9af3499791bd3a3daae21 < fd37f9dd5b5ab70a46fa7bc76623c0528d602b27
Linux / Linux
4.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/6e164ba1057175fb8a370d8e05cbff5c57eac0c8 git.kernel.org: https://git.kernel.org/stable/c/1474f3970d1afd303e12ff14d06808eabb371576 git.kernel.org: https://git.kernel.org/stable/c/07fe270ec07c138a70afe7a81e115a85c35c545c git.kernel.org: https://git.kernel.org/stable/c/fd37f9dd5b5ab70a46fa7bc76623c0528d602b27