SB2026072748 - Out-of-bounds read in Linux kernel amd amdgpu driver
Published: July 27, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2026-64516)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds access in the amdgpu VCE 1 firmware loading and memory cache setup code when processing firmware microcode and calculating buffer offsets and sizes. A local user can provide specially crafted firmware data to trigger an out-of-bounds access and cause a denial of service.
The issue involves incorrect accounting for the firmware offset within the VCPU buffer object and improper alignment and bounds validation for reserved firmware, stack, and data regions.
Remediation
Install update from vendor's website.