SB2026090526 - Integer overflow in Linux kernel amd amdgpu driver
Published: September 5, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Integer overflow (CVE-ID: CVE-2026-80909)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause an integer overflow during minimum DPB size calculation.
The vulnerability exists due to improper validation of the H.265 reference count in the AMDGPU UVD message decoder when decoding UVD messages. A local user can submit a UVD message with an invalid number of H.265 references to cause an integer overflow during minimum DPB size calculation.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0acdf1a575f59bd46717d5c487d84575af5bee8f
- https://git.kernel.org/stable/c/1facad2a78c1a8aeecc36eb4d560c7f1e10ce198
- https://git.kernel.org/stable/c/2abcdc5f738574e7fcdd9417575dffb877fdc26f
- https://git.kernel.org/stable/c/499907e5d46e575e96967c0230a0a6af980a17ab
- https://git.kernel.org/stable/c/9fca434208f1f9ab977feac62df8ebb1cc7ce893
- https://git.kernel.org/stable/c/a930c54cb67200de8bc0de87480d09ece7dcd85d
- https://git.kernel.org/stable/c/cbf1c84bf5cac2b3742ea3d2085fa713424465cc
- https://git.kernel.org/stable/c/e304c3e0d9ce251887be1f274aa0ed52219d5fd7