Junglewise Threat Intelligence

CVE-2026-63878: Linux Kernel amdgpu denial of service in GEM_OP ioctl

CVE-2026-63878 · Severity: info · CVSS 5.5 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's AMD GPU driver could allow a local user to crash the system. By providing an excessively large value during a specific graphics memory operation, an attacker can trigger a kernel panic. This results in a complete system outage, affecting availability and ongoing operations.

Technical details

A vulnerability exists in the amdgpu driver within the Linux kernel due to a lack of bounds checking on user-supplied input. Specifically, the 'num_entries' field in the GEM_OP GET_MAPPING_INFO ioctl is passed directly to kvcalloc(). Because 'num_entries' is a 32-bit unsigned integer and the size of each entry is 32 bytes, a large value can result in an allocation size exceeding INT_MAX. This triggers a WARNING in the kernel's memory allocator, which leads to a kernel panic on systems configured with CONFIG_PANIC_ON_WARN=y. The issue has been resolved by adding a size bounds check before the allocation.

Affected products

  • Linux Linux Kernel 6.18 to 6.18.35, 7.0 to 7.0.12

Timeline

  • 2026-07-19: disclosed
  • 2026-07-19: advisory

References

Related threats