7.1
/ 10
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Description
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: Add bounds checking to ib_{get,set}_value
The uvd/vce/vcn code accesses the IB at predefined offsets without
checking that the IB is large enough. Check the bounds here. The caller
is responsible for making sure it can handle arbitrary return values.
Also make the idx a uint32_t to prevent overflows causing the condition
to fail.
drm/amdgpu: Add bounds checking to ib_{get,set}_value
The uvd/vce/vcn code accesses the IB at predefined offsets without
checking that the IB is large enough. Check the bounds here. The caller
is responsible for making sure it can handle arbitrary return values.
Also make the idx a uint32_t to prevent overflows causing the condition
to fail.
Basic Information
ID
CVE-2026-46218
Source
Linux
Published
May 28, 2026 at 09:40
Modified
May 30, 2026 at 10:49
Affected Product
Vendor
Linux
Product
Linux
Version
d38ceaf99ed015f2a0b9af3499791bd3a3daae21
Affected Versions
Linux Linux d38ceaf99ed015f2a0b9af3499791bd3a3daae21
Linux Linux d38ceaf99ed015f2a0b9af3499791bd3a3daae21
Linux Linux d38ceaf99ed015f2a0b9af3499791bd3a3daae21
Linux Linux d38ceaf99ed015f2a0b9af3499791bd3a3daae21
Linux Linux d38ceaf99ed015f2a0b9af3499791bd3a3daae21
Linux Linux 4.2
Linux Linux d38ceaf99ed015f2a0b9af3499791bd3a3daae21
Linux Linux d38ceaf99ed015f2a0b9af3499791bd3a3daae21
Linux Linux d38ceaf99ed015f2a0b9af3499791bd3a3daae21
Linux Linux d38ceaf99ed015f2a0b9af3499791bd3a3daae21
Linux Linux 4.2
References
- git.kernel.org /stable/c/0fb5cb556b249b2b64c0f818136c4c3e838ef53f
- git.kernel.org /stable/c/a853178d23e774adfe3a35073c375b04b3b20f7d
- git.kernel.org /stable/c/fec8b11b55e53ff51a741e56894fe331a516f5c6
- git.kernel.org /stable/c/ee26fcf7c5cf131f0b6a732faa27d79ec61b8ec7
- git.kernel.org /stable/c/66085e206431ef88ce36f53c1f53d570790ccc9e