SB2026090620 - Incorrect Calculation of Buffer Size in Linux kernel amd amdgpu driver



SB2026090620 - Incorrect Calculation of Buffer Size in Linux kernel amd amdgpu driver

Published: September 6, 2026

Security Bulletin ID SB2026090620
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Incorrect Calculation of Buffer Size (CVE-ID: CVE-2026-80907)

CWE-ID: CWE-131 - Incorrect Calculation of Buffer Size

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an incorrect calculation of the decoded picture buffer minimum size in the amdgpu UVD H.264 decode message handler when processing H.264 decode messages. A local user can submit a crafted H.264 decode message to cause a denial of service.


Remediation

Install update from vendor's website.