Executive brief
The Linux kernel's AMD GPU driver contains a flaw in the UVD (Unified Video Decoder) component that can cause a system crash when processing video frames with invalid dimensions. An attacker could exploit this by providing specially crafted video data, leading to a denial of service that freezes or reboots affected systems.
Technical details
This is a division-by-zero vulnerability in the AMD GPU UVD decoder (drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c). When video frame width or height values are less than 16 pixels, intermediate calculations (width_in_mb and height_in_mb) become zero, which subsequently causes fs_in_mb to be zero. This zero value is then used as a divisor when calculating num_dpb_buffer in H.264 and H.264 Performance decode paths, triggering a kernel panic. The fix adds input validation to reject frames with dimensions smaller than 16×16 before any calculations are performed. The vulnerability is reachable via malformed video decode requests, and the patch was authored by Boyuan Zhang and merged into mainline and stable kernel branches.
Affected products
- Linux Linux kernel Multiple versions prior to patch (2026-08-10)
Timeline
- 2026-08-10: disclosed: CVE-2026-68106 published
- 2026-05-12: patched: Upstream fix committed by Boyuan Zhang
- 2026-08-19: patched: Backported to stable kernel branches