Out-of-bounds read in Linux kernel - CVE-2026-64516
Published: July 27, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds access in the amdgpu VCE 1 firmware loading and memory cache setup code when processing firmware microcode and calculating buffer offsets and sizes. A local user can provide specially crafted firmware data to trigger an out-of-bounds access and cause a denial of service.
The issue involves incorrect accounting for the firmware offset within the VCPU buffer object and improper alignment and bounds validation for reserved firmware, stack, and data regions.
Affected software
Ubuntu
linux-aws (Ubuntu package)
linux-gcp-7.0 (Ubuntu package)
linux-nvidia (Ubuntu package)
linux-nvidia-bos (Ubuntu package)
How to mitigate CVE-2026-64516
linux-aws (Ubuntu package) - addressed in versions 7.0.0-1009.9, 7.0.0-1015.15
linux-gcp-7.0 (Ubuntu package) - update to 7.0.0-1011.11~24.04.1
linux-nvidia (Ubuntu package) - addressed in versions 7.0.0-1016.16, 7.0.0-1016.16~24.04.1
linux-nvidia-bos (Ubuntu package) - update to 7.0.0-2016.16