Executive brief
A vulnerability was identified in the Linux kernel's AMD GPU driver (amdgpu) specifically affecting Video Core Next (VCN) 4.0 hardware. The issue involves how the driver reads command buffers (Indirect Buffers) sent to the graphics processor. If exploited, this could lead to an out-of-bounds memory read, potentially causing system instability or a crash, though it typically requires local access to the system.
Technical details
An out-of-bounds (OOB) read vulnerability exists in the 'vcn_v4_0' component of the Linux kernel's amdgpu driver. The root cause is insufficient bounds checking during the parsing of Indirect Buffers (IB) within the 'vcn_v4_0_enc_find_ib_param' and 'vcn_v4_0_ring_patch_cs_in_place' functions. An attacker with the ability to submit specially crafted command streams to the GPU could trigger reads beyond the allocated buffer. The fix involves rewriting the parsing logic to use 'amdgpu_ib_get_value()', which implements proper bounds validation. The vulnerability was patched in various stable branches of the Linux kernel in May 2026.
Affected products
- Linux Linux Kernel VCN 4.0 (amdgpu) driver
Timeline
- 2026-03-24: other: Patch authored
- 2026-05-28: advisory: CVE published
References
- https://git.kernel.org/stable/c/1dc005775fb5b3f86464406452b17364f85581d3
- https://git.kernel.org/stable/c/2444eb0ec8283f4a3845eb7febad378476e1ba3c
- https://git.kernel.org/stable/c/5c3e8ebad0c9e2354ddfa8f2148dc4f70a3b4bd1
- https://git.kernel.org/stable/c/a6d5563ba1f03a049561cd347574613167294e8d
- https://git.kernel.org/stable/c/d0802a8877d730260d4af4dd4e0b6cde7e0e593f