Out-of-bounds write in Linux kernel - CVE-2026-80576
Published: August 27, 2026
Vulnerability details
The vulnerability allows a local user to corrupt memory and cause a denial of service.
The vulnerability exists due to an out-of-bounds write in amdgpu_cs_p2_ib() when processing user-supplied indirect buffer lengths for command submission. A local user can submit an oversized indirect buffer to corrupt memory and cause a denial of service.
The issue affects GFX rings and can destabilize command submission because the indirect buffer length is encoded into packet control fields.