Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q3hq-vwmg-m826

Опубликовано: 25 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu/vce1: Fix VCE 1 firmware size and offsets

The VCPU BO contains the actual FW at an offset, but it was not calculated into the VCPU BO size. Subtract this from the FW size to make sure there is no out of bounds access.

Make sure the stack and data offsets are aligned to the 32K TLB size.

Check that the FW microcode actually fits in the space that is reserved for it.

(cherry picked from commit c16fe59f622a080fc457a57b3e8f14c780699449)

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu/vce1: Fix VCE 1 firmware size and offsets

The VCPU BO contains the actual FW at an offset, but it was not calculated into the VCPU BO size. Subtract this from the FW size to make sure there is no out of bounds access.

Make sure the stack and data offsets are aligned to the 32K TLB size.

Check that the FW microcode actually fits in the space that is reserved for it.

(cherry picked from commit c16fe59f622a080fc457a57b3e8f14c780699449)

EPSS

Процентиль: 2%
0.00112
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
7 дней назад

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vce1: Fix VCE 1 firmware size and offsets The VCPU BO contains the actual FW at an offset, but it was not calculated into the VCPU BO size. Subtract this from the FW size to make sure there is no out of bounds access. Make sure the stack and data offsets are aligned to the 32K TLB size. Check that the FW microcode actually fits in the space that is reserved for it. (cherry picked from commit c16fe59f622a080fc457a57b3e8f14c780699449)

CVSS3: 7
redhat
8 дней назад

A flaw was found in the Linux kernel's `drm/amdgpu/vce1` component. The vulnerability arises from incorrect calculations of the VCE 1 firmware size and offsets, which could lead to an out-of-bounds access. This issue could potentially allow a local attacker to cause system instability or a denial of service (DoS) by manipulating the firmware handling.

CVSS3: 8.8
nvd
7 дней назад

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vce1: Fix VCE 1 firmware size and offsets The VCPU BO contains the actual FW at an offset, but it was not calculated into the VCPU BO size. Subtract this from the FW size to make sure there is no out of bounds access. Make sure the stack and data offsets are aligned to the 32K TLB size. Check that the FW microcode actually fits in the space that is reserved for it. (cherry picked from commit c16fe59f622a080fc457a57b3e8f14c780699449)

CVSS3: 8.8
debian
7 дней назад

In the Linux kernel, the following vulnerability has been resolved: d ...

EPSS

Процентиль: 2%
0.00112
Низкий

8.8 High

CVSS3