Executive brief
A vulnerability was identified in the Linux kernel's AMD graphics driver (amdgpu) specifically affecting systems using Video Core Next (VCN) 4 hardware. The issue allows for potential out-of-bounds memory reads when the system processes video decoding messages. This could lead to system instability or the unintended exposure of sensitive information from the computer's memory to a local user.
Technical details
An out-of-bounds (OOB) read vulnerability exists in the 'vcn_v4_0_dec_msg' function within 'drivers/gpu/drm/amd/amdgpu/vcn_v4_0.c'. The root cause is insufficient validation of the message length and buffer counts provided in the decoder message against the actual size of the Buffer Object (BO). A local attacker could provide a crafted video decoding message with a large number of buffers or an invalid length, causing the kernel to read memory beyond the allocated buffer. This has been resolved by adding explicit bounds checks against the end of the BO whenever the message or its buffer indices are accessed.
Affected products
- Linux Linux Kernel VCN4-enabled versions prior to the fix
Timeline
- 2026-03-25: other: Initial patch authored
- 2026-05-17: patched: Patch applied to stable kernel branches
- 2026-05-28: disclosed: CVE published
References
- https://git.kernel.org/stable/c/0a78f2bac1424deb7c9d5e09c6b8e849d8e8b648
- https://git.kernel.org/stable/c/3c817a60b09eaab926e475088e750936efcc95ae
- https://git.kernel.org/stable/c/63b51e8a9d54317d31cc3856c1e12407070d5fc2
- https://git.kernel.org/stable/c/7688143ca62edeecacb3ba0a2cea129dbd262a18
- https://git.kernel.org/stable/c/c72a8b4dc6d598e3831ef3abd9c6527dfbf4810e