SB2026090526 - Integer overflow in Linux kernel amd amdgpu driver



SB2026090526 - Integer overflow in Linux kernel amd amdgpu driver

Published: September 5, 2026

Security Bulletin ID SB2026090526
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Integer overflow (CVE-ID: CVE-2026-80909)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause an integer overflow during minimum DPB size calculation.

The vulnerability exists due to improper validation of the H.265 reference count in the AMDGPU UVD message decoder when decoding UVD messages. A local user can submit a UVD message with an invalid number of H.265 references to cause an integer overflow during minimum DPB size calculation.


Remediation

Install update from vendor's website.