SB2026082797 - Integer overflow in Linux kernel amd amdgpu driver
Published: August 27, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Integer overflow (CVE-ID: CVE-2026-80540)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to an integer overflow in the amdgpu UVD decode message handler when processing crafted decode parameters. A local user can supply a crafted pitch value to trigger the overflow and execute arbitrary code.
The issue is in the Linux kernel DRM AMDGPU UVD decode path.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/25ee120f3803ad9e416ef9f76f4c3234cc4d645b
- https://git.kernel.org/stable/c/271a7da84a6262a09de549912dcf6a749d169cb6
- https://git.kernel.org/stable/c/5cbd8af02b0b9c8723fa30edcf6fccab5170af8d
- https://git.kernel.org/stable/c/60539d517e8439621532d8c01091ac049c596b4b
- https://git.kernel.org/stable/c/b7549e3f96c78921751c4b3e69af729662130d83
- https://git.kernel.org/stable/c/b8bb9ba3f101a1b0011f785a577a4a0a38371174
- https://git.kernel.org/stable/c/bc7397a033ac52f6d8c9bb6510d61694b2a3fce7
- https://git.kernel.org/stable/c/d058f7a6709441afe1784eecd8c0643dd84750bc