CVE-2026-80540

Source
https://cve.org/CVERecord?id=CVE-2026-80540
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80540.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-80540
Downstream
Published
2026-08-26T14:37:13Z
Modified
2026-08-28T03:47:28Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
drm/amdgpu: Fix UVD decode image min size calculation
Details

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu: Fix UVD decode image min size calculation

This needs to use pitch instead of width. Also reject pitch over 4096 to avoid overflow.

(cherry picked from commit b41c8cb12e202b220353332ab87dc01a11f69304)

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80540.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
d38ceaf99ed015f2a0b9af3499791bd3a3daae21
Fixed
bc7397a033ac52f6d8c9bb6510d61694b2a3fce7
Fixed
d058f7a6709441afe1784eecd8c0643dd84750bc
Fixed
b7549e3f96c78921751c4b3e69af729662130d83
Fixed
60539d517e8439621532d8c01091ac049c596b4b
Fixed
271a7da84a6262a09de549912dcf6a749d169cb6
Fixed
25ee120f3803ad9e416ef9f76f4c3234cc4d645b
Fixed
5cbd8af02b0b9c8723fa30edcf6fccab5170af8d
Fixed
b8bb9ba3f101a1b0011f785a577a4a0a38371174

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80540.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.2.0
Fixed
5.10.266
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.217
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.184
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.153
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.105
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.46
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.10

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80540.json"