From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0487A43BDB4 for ; Wed, 26 Aug 2026 14:41:06 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787755270; cv=none; b=VbAKgjIRti+rfRyp+twu3vSVWZERGhBwiF0Jgyw0idoQyIMGcmXNgz3dqUMWoLODD3XGSe1NqZpLPU+Kzf6tKdWnz1ydRySGVUsSMpmCFuhSPRv5mAhXlQSA3X2mwlsmA4bgOy69hojOGSuVqcv5vr/uloVvHE9dJdGBWsqj0OY= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787755270; c=relaxed/simple; bh=NVPx7YdkcSdJIPUu0bicX0YqHhhrzwWTqgI4Vcc7SGI=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=ML0WQ45MpTFPpEb6x6MW4Aux/7QoV0vKn9Hq5+i3B0lG3ubl46DcwgbmhSfzXAx+WLeTDu8bNwImQYypgsI5+WBS4U+8WheH1s+7iTOMwuqm3OnWPh9C9p8jm2EzSpwP95onuajSYW2uuAdhBGdY+3lUdRYQk5OHaKMJxkmXjK0= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=PBag8tFh; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="PBag8tFh" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 437E81F000E9; Wed, 26 Aug 2026 14:41:03 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1787755263; bh=zBl/3SAWrw8gwqxMrI6U76p35RiL71pejE9TNDVTS2I=; h=From:To:Cc:Subject:Date:Reply-To; b=PBag8tFhWtsR4yAFFQjXgZWtgIcGTL4KiSLnWNC9SBPJcgwhhfyKp3rBsAgtnkw2i HVI4nboub2mnbU7h9D/vUpDrkYbo9ISBB+Sf7Yt2SzOk7xTKomBaE2I46uqZkq3ia2 0KVnrM6pVZVUnmOsJdLikxRF7xUBHPLaQUf67NTc= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-80540: drm/amdgpu: Fix UVD decode image min size calculation Date: Wed, 26 Aug 2026 16:37:36 +0200 Message-ID: <2026082605-CVE-2026-80540-2460@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=2657; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=q6Y78UkIGlfS+VBx9VPWHiIOosGK/tobvZKnhWaZX5o=; b=owGbwMvMwCRo6H6F97bub03G02pJDFl9vwTd5hbte7TcNPnowr6j3W4aV61yt7kz5zxozhF60 Lo+znZSRywLgyATg6yYIsuXbTxH91ccUvQytD0NM4eVCWQIAxenAEykLoFhwUKXmlg178xpkuqZ TYV5/5ZuWbPGgWHBjopFBYc9d6xrNLZrufgrda+w1P73AA== X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix UVD decode image min size calculation This needs to use pitch instead of width. Also reject pitch over 4096 to avoid overflow. (cherry picked from commit b41c8cb12e202b220353332ab87dc01a11f69304) The Linux kernel CVE team has assigned CVE-2026-80540 to this issue. Affected and fixed versions =========================== Fixed in 5.10.266 with commit bc7397a033ac52f6d8c9bb6510d61694b2a3fce7 Fixed in 5.15.217 with commit d058f7a6709441afe1784eecd8c0643dd84750bc Fixed in 6.1.184 with commit b7549e3f96c78921751c4b3e69af729662130d83 Fixed in 6.6.153 with commit 60539d517e8439621532d8c01091ac049c596b4b Fixed in 6.12.105 with commit 271a7da84a6262a09de549912dcf6a749d169cb6 Fixed in 6.18.46 with commit 25ee120f3803ad9e416ef9f76f4c3234cc4d645b Fixed in 7.1.10 with commit 5cbd8af02b0b9c8723fa30edcf6fccab5170af8d Fixed in 7.2 with commit b8bb9ba3f101a1b0011f785a577a4a0a38371174 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-80540 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/bc7397a033ac52f6d8c9bb6510d61694b2a3fce7 https://git.kernel.org/stable/c/d058f7a6709441afe1784eecd8c0643dd84750bc https://git.kernel.org/stable/c/b7549e3f96c78921751c4b3e69af729662130d83 https://git.kernel.org/stable/c/60539d517e8439621532d8c01091ac049c596b4b https://git.kernel.org/stable/c/271a7da84a6262a09de549912dcf6a749d169cb6 https://git.kernel.org/stable/c/25ee120f3803ad9e416ef9f76f4c3234cc4d645b https://git.kernel.org/stable/c/5cbd8af02b0b9c8723fa30edcf6fccab5170af8d https://git.kernel.org/stable/c/b8bb9ba3f101a1b0011f785a577a4a0a38371174