All of lore.kernel.org
 help / color / mirror / Atom feed
* CVE-2026-80576: drm/amdgpu: reject oversized IBs with per-ring packet limits
@ 2026-08-26 14:38 Greg Kroah-Hartman
  0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-08-26 14:38 UTC (permalink / raw)
  To: linux-cve-announce; +Cc: Greg Kroah-Hartman

From: Greg Kroah-Hartman <gregkh@kernel.org>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu: reject oversized IBs with per-ring packet limits

On GFX rings, amdgpu_cs_p2_ib() passed user-supplied ib_bytes through
to ib->length_dw without a limit, while ring_emit_ib() encodes length
into packet fields. Oversized values can corrupt adjacent control bits
and destabilize command submission.

Add a per-ring IB packet size limit helper and reject command
submissions exceeding the corresponding dword limit before IB
allocation. Use the documented 20-bit limit for GFX/compute/SDMA/VPE,
and apply the MM fallback limit for other ring types.

(cherry picked from commit 7f48fa2cf62e3fa6c9c3870aa74988f773247e52)

The Linux kernel CVE team has assigned CVE-2026-80576 to this issue.


Affected and fixed versions
===========================

	Fixed in 6.12.105 with commit 6e164ba1057175fb8a370d8e05cbff5c57eac0c8
	Fixed in 6.18.46 with commit 1474f3970d1afd303e12ff14d06808eabb371576
	Fixed in 7.1.10 with commit 07fe270ec07c138a70afe7a81e115a85c35c545c
	Fixed in 7.2 with commit fd37f9dd5b5ab70a46fa7bc76623c0528d602b27

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-80576
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/6e164ba1057175fb8a370d8e05cbff5c57eac0c8
	https://git.kernel.org/stable/c/1474f3970d1afd303e12ff14d06808eabb371576
	https://git.kernel.org/stable/c/07fe270ec07c138a70afe7a81e115a85c35c545c
	https://git.kernel.org/stable/c/fd37f9dd5b5ab70a46fa7bc76623c0528d602b27

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2026-08-26 14:40 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-26 14:38 CVE-2026-80576: drm/amdgpu: reject oversized IBs with per-ring packet limits Greg Kroah-Hartman

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.