8.8

CVE-2026-80576

drm/amdgpu: reject oversized IBs with per-ring packet limits

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu: reject oversized IBs with per-ring packet limits

On GFX rings, amdgpu_cs_p2_ib() passed user-supplied ib_bytes through
to ib->length_dw without a limit, while ring_emit_ib() encodes length
into packet fields. Oversized values can corrupt adjacent control bits
and destabilize command submission.

Add a per-ring IB packet size limit helper and reject command
submissions exceeding the corresponding dword limit before IB
allocation. Use the documented 20-bit limit for GFX/compute/SDMA/VPE,
and apply the MM fallback limit for other ring types.

(cherry picked from commit 7f48fa2cf62e3fa6c9c3870aa74988f773247e52)
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version d38ceaf99ed015f2a0b9af3499791bd3a3daae21
Version < 6e164ba1057175fb8a370d8e05cbff5c57eac0c8
Status affected
Version d38ceaf99ed015f2a0b9af3499791bd3a3daae21
Version < 1474f3970d1afd303e12ff14d06808eabb371576
Status affected
Version d38ceaf99ed015f2a0b9af3499791bd3a3daae21
Version < 07fe270ec07c138a70afe7a81e115a85c35c545c
Status affected
Version d38ceaf99ed015f2a0b9af3499791bd3a3daae21
Version < fd37f9dd5b5ab70a46fa7bc76623c0528d602b27
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 4.2
Status affected
Version 0
Version < 4.2
Status unaffected
Version <= 6.12.*
Version 6.12.105
Status unaffected
Version <= 6.18.*
Version 6.18.46
Status unaffected
Version <= 7.1.*
Version 7.1.10
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.02
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 8.8 2 6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/6e164ba1057175fb8a370d8e05cbff5c57eac0c8
https://git.kernel.org/stable/c/1474f3970d1afd303e12ff14d06808eabb371576
https://git.kernel.org/stable/c/07fe270ec07c138a70afe7a81e115a85c35c545c
https://git.kernel.org/stable/c/fd37f9dd5b5ab70a46fa7bc76623c0528d602b27