Junglewise Threat Intelligence

CVE-2026-23468: Linux Kernel amdgpu resource exhaustion in BO list creation

CVE-2026-23468 · Severity: info · CVSS 0 · Published 2026-04-03

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's AMD graphics driver could allow a local user to crash the system or cause significant slowdowns. By requesting an extremely large number of buffer objects, an attacker can force the system to exhaust its available memory. This results in a denial-of-service condition, impacting the availability of the affected machine.

Technical details

A resource exhaustion vulnerability exists in the amdgpu driver within the Linux kernel. The 'amdgpu_bo_create_list_entry_array' function in 'amdgpu_bo_list.c' allowed userspace to provide an arbitrary 'bo_number' value. While existing checks prevented integer overflows during allocation, they did not prevent valid but excessively large allocations that could consume gigabytes of system memory. An attacker with local access could exploit this to trigger an Out-of-Memory (OOM) condition or cause long kernel processing times. The fix introduces a hard limit of 128k entries (AMDGPU_BO_LIST_MAX_ENTRIES) per BO list.

Affected products

  • Linux Linux Kernel amdgpu driver

Timeline

  • 2026-04-03: disclosed: Initial publication of the vulnerability record.
  • 2026-03-17: patched: Mainline kernel patch committed.

References

Related threats