CVE-2026-80576

Source
https://cve.org/CVERecord?id=CVE-2026-80576
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80576.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-80576
Downstream
Published
2026-08-26T14:37:35.538Z
Modified
2026-08-28T03:47:29.321128694Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
drm/amdgpu: reject oversized IBs with per-ring packet limits
Details

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu: reject oversized IBs with per-ring packet limits

On GFX rings, amdgpucsp2ib() passed user-supplied ibbytes through to ib->lengthdw without a limit, while ringemit_ib() encodes length into packet fields. Oversized values can corrupt adjacent control bits and destabilize command submission.

Add a per-ring IB packet size limit helper and reject command submissions exceeding the corresponding dword limit before IB allocation. Use the documented 20-bit limit for GFX/compute/SDMA/VPE, and apply the MM fallback limit for other ring types.

(cherry picked from commit 7f48fa2cf62e3fa6c9c3870aa74988f773247e52)

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80576.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
d38ceaf99ed015f2a0b9af3499791bd3a3daae21
Fixed
6e164ba1057175fb8a370d8e05cbff5c57eac0c8
Fixed
1474f3970d1afd303e12ff14d06808eabb371576
Fixed
07fe270ec07c138a70afe7a81e115a85c35c545c
Fixed
fd37f9dd5b5ab70a46fa7bc76623c0528d602b27

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80576.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.2.0
Fixed
6.12.105
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.46
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.10

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80576.json"