SB2026090620 - Incorrect Calculation of Buffer Size in Linux kernel amd amdgpu driver
Published: September 6, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Incorrect Calculation of Buffer Size (CVE-ID: CVE-2026-80907)
CWE-ID: CWE-131 - Incorrect Calculation of Buffer Size
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an incorrect calculation of the decoded picture buffer minimum size in the amdgpu UVD H.264 decode message handler when processing H.264 decode messages. A local user can submit a crafted H.264 decode message to cause a denial of service.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/21a8084cd76223a13493237e04d45f5226d7cee6
- https://git.kernel.org/stable/c/33f4ef585368fe93523dca1e5440e006f6e5146e
- https://git.kernel.org/stable/c/38914cb2c6afb5fe00241ea3438e655822196378
- https://git.kernel.org/stable/c/fa96c24485942e277483cc70d9551d9e0111d7c5
- https://git.kernel.org/stable/c/ff4361816b6ba4bd29b548b17d993056a1ae2502