All of lore.kernel.org
 help / color / mirror / Atom feed
From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
To: linux-cve-announce@vger.kernel.org
Cc: Greg Kroah-Hartman <gregkh@kernel.org>
Subject: CVE-2026-80540: drm/amdgpu: Fix UVD decode image min size calculation
Date: Wed, 26 Aug 2026 16:37:36 +0200	[thread overview]
Message-ID: <2026082605-CVE-2026-80540-2460@gregkh> (raw)

From: Greg Kroah-Hartman <gregkh@kernel.org>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu: Fix UVD decode image min size calculation

This needs to use pitch instead of width. Also reject pitch
over 4096 to avoid overflow.

(cherry picked from commit b41c8cb12e202b220353332ab87dc01a11f69304)

The Linux kernel CVE team has assigned CVE-2026-80540 to this issue.


Affected and fixed versions
===========================

	Fixed in 5.10.266 with commit bc7397a033ac52f6d8c9bb6510d61694b2a3fce7
	Fixed in 5.15.217 with commit d058f7a6709441afe1784eecd8c0643dd84750bc
	Fixed in 6.1.184 with commit b7549e3f96c78921751c4b3e69af729662130d83
	Fixed in 6.6.153 with commit 60539d517e8439621532d8c01091ac049c596b4b
	Fixed in 6.12.105 with commit 271a7da84a6262a09de549912dcf6a749d169cb6
	Fixed in 6.18.46 with commit 25ee120f3803ad9e416ef9f76f4c3234cc4d645b
	Fixed in 7.1.10 with commit 5cbd8af02b0b9c8723fa30edcf6fccab5170af8d
	Fixed in 7.2 with commit b8bb9ba3f101a1b0011f785a577a4a0a38371174

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-80540
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/bc7397a033ac52f6d8c9bb6510d61694b2a3fce7
	https://git.kernel.org/stable/c/d058f7a6709441afe1784eecd8c0643dd84750bc
	https://git.kernel.org/stable/c/b7549e3f96c78921751c4b3e69af729662130d83
	https://git.kernel.org/stable/c/60539d517e8439621532d8c01091ac049c596b4b
	https://git.kernel.org/stable/c/271a7da84a6262a09de549912dcf6a749d169cb6
	https://git.kernel.org/stable/c/25ee120f3803ad9e416ef9f76f4c3234cc4d645b
	https://git.kernel.org/stable/c/5cbd8af02b0b9c8723fa30edcf6fccab5170af8d
	https://git.kernel.org/stable/c/b8bb9ba3f101a1b0011f785a577a4a0a38371174

                 reply	other threads:[~2026-08-26 14:41 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=2026082605-CVE-2026-80540-2460@gregkh \
    --to=gregkh@linuxfoundation.org \
    --cc=cve@kernel.org \
    --cc=gregkh@kernel.org \
    --cc=linux-cve-announce@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.