CVE-2026-74417

Source
https://cve.org/CVERecord?id=CVE-2026-74417
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74417.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-74417
Downstream
Published
2026-08-15T05:59:22Z
Modified
2026-08-18T03:56:57Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
drm/radeon: fix integer overflow in radeon_align_pitch()
Details

In the Linux kernel, the following vulnerability has been resolved:

drm/radeon: fix integer overflow in radeon_align_pitch()

radeon_align_pitch() has the same kind of overflow issue as the old amdgpu helper: both the alignment round-up add and the final 'aligned * cpp' calculation can overflow signed int.

If that wraps, radeon_mode_dumb_create() can end up returning an invalid pitch or creating a zero-sized dumb buffer.

Fix this by using check_add_overflow() for the alignment round-up and check_mul_overflow() for the final pitch calculation, returning 0 on overflow. Also reject zero pitch and size in radeon_mode_dumb_create().

Found via AST-based call-graph analysis using sqry.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74417.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ff72145badb834e8051719ea66e024784d000cb4
Fixed
b7b44937c548c2c987fcdd129f8896741004bed6
Fixed
415bb9893e249e46aa5159f7363a11512cf06fa9
Fixed
d9dfa176899d488e48bb7342d2c43ddd36e66318
Fixed
dfc7b5b5599472277e71e5bd2712740651c7c5be
Fixed
ce3b24eb3ee8f82de851535f516bf21f83e82259

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74417.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.39
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74417.json"