Out-of-bounds write in Linux kernel - CVE-2026-80576

 

Out-of-bounds write in Linux kernel - CVE-2026-80576

Published: August 27, 2026


Vulnerability identifier: #VU145915
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-80576
CWE-ID: CWE-787
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to corrupt memory and cause a denial of service.

The vulnerability exists due to an out-of-bounds write in amdgpu_cs_p2_ib() when processing user-supplied indirect buffer lengths for command submission. A local user can submit an oversized indirect buffer to corrupt memory and cause a denial of service.

The issue affects GFX rings and can destabilize command submission because the indirect buffer length is encoded into packet control fields.


Affected software

Linux kernel

How to mitigate CVE-2026-80576

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins