Executive brief
The Linux kernel's Radeon graphics driver contains an integer overflow vulnerability in a function that calculates the pitch (row width in bytes) for graphics buffers. An attacker with local access could exploit this to create zero-sized or invalid buffers, potentially leading to denial of service or memory corruption on systems using Radeon GPUs.
Technical details
The vulnerability is an integer overflow issue in the radeon_align_pitch() function in drivers/gpu/drm/radeon/radeon_gem.c. Both the alignment round-up addition and the final multiplication of aligned pitch by bytes-per-pixel (cpp) can overflow a signed integer, wrapping to invalid or zero values. This occurs when large width values are processed. The vulnerability affects the radeon_mode_dumb_create() function, which uses the result to allocate graphics buffers. An attacker with local file descriptor access can trigger buffer creation with malformed dimensions. The fix uses check_add_overflow() and check_mul_overflow() kernel macros to detect overflow conditions and return an error instead of wrapping values. Patches are available in the Linux kernel stable trees.
Affected products
- Linux Linux Kernel Multiple versions; patched in stable releases
Timeline
- 2026-08-15: disclosed: CVE-2026-74417 published
- 2026-07-24: patched: Patch committed to Linux kernel stable tree