SB2026052965 - Out-of-bounds read in Linux kernel amd amdgpu driver
Published: May 29, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2026-46230)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in the amdgpu vcn3 decoder message parser when parsing decoder messages from a buffer object. A local user can supply a specially crafted decoder message to disclose sensitive information.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/638d3e0b9eb77aa53fdd60e2b928761d16ba76fa
- https://git.kernel.org/stable/c/638e48ee39d0f2af9336f917a6f5d6692dd64d93
- https://git.kernel.org/stable/c/870c8738c3774336baedddd0240951d078a703b8
- https://git.kernel.org/stable/c/b193019860d61e92da395eae2011f2f6716b182f
- https://git.kernel.org/stable/c/e382e0b81a3e7bd21504fee1d01ae8b08f84d3a7