« Volver al listado

CVE-2026-68276

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu/gfx: fix cleaner shader IB buffer overflow

The cleaner shader sysfs path allocates a 16-dword (64 byte) IB but incorrectly fills (align_mask + 1) dwords. On GFX rings align_mask is 0xff, so the loop wrote 256 dwords into a 64-byte buffer, causing a kernel page fault.

The IB only needs to be a minimal NOP shell to schedule the job; the cleaner shader itself is emitted on the ring via emit_cleaner_shader(). Fill 16 dwords to match the allocation.

v2: Use ib_size_dw variable (Lijo)

(cherry picked from commit bf21af331ebf72d0935fd70c73192414a422c03a)

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-68276",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "d361ad5d2fc0e4d59d5d538092c9b37889756642",
              "lessThan": "201633f47b542a99bb7baafdfcda7781249fb3d9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "d361ad5d2fc0e4d59d5d538092c9b37889756642",
              "lessThan": "e28420e36542ae8b66a5bdcec419525f521bddf8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "d361ad5d2fc0e4d59d5d538092c9b37889756642",
              "lessThan": "9cd9a983769a4d0e9cc80a287316ee79685d38b3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "d361ad5d2fc0e4d59d5d538092c9b37889756642",
              "lessThan": "3e864bf2a32a1cbdf1e0f9c5a5a4176e8575f4a3",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/gpu/drm/amd/amdgpu/amdgpu_gfx.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.12"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.12",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.103",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.42",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/gpu/drm/amd/amdgpu/amdgpu_gfx.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-10T13:20:16.693",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/201633f47b542a99bb7baafdfcda7781249fb3d9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/3e864bf2a32a1cbdf1e0f9c5a5a4176e8575f4a3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9cd9a983769a4d0e9cc80a287316ee79685d38b3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e28420e36542ae8b66a5bdcec419525f521bddf8",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/gfx: fix cleaner shader IB buffer overflow\n\nThe cleaner shader sysfs path allocates a 16-dword (64 byte) IB but\nincorrectly fills (align_mask + 1) dwords. On GFX rings align_mask is\n0xff, so the loop wrote 256 dwords into a 64-byte buffer, causing a\nkernel page fault.\n\nThe IB only needs to be a minimal NOP shell to schedule the job; the\ncleaner shader itself is emitted on the ring via emit_cleaner_shader().\nFill 16 dwords to match the allocation.\n\nv2: Use ib_size_dw variable (Lijo)\n\n(cherry picked from commit bf21af331ebf72d0935fd70c73192414a422c03a)"
    }
  ],
  "lastModified": "2026-08-17T05:18:30.190",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}