In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/vcn4: avoid rereading IB param length
Reuse the parameter length returned by vcn_v4_0_enc_find_ib_param() instead of rereading it from the IB.
This avoids a potential TOCTOU issue if the IB contents change between reads.
(cherry picked from commit dbb02b4755f8c1f3773263f2d779872c1c0c073a)
{
"cna_assigner": "Linux",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68107.json"
}