Количество 5
Количество 5
CVE-2026-89818
(In the Linux kernel, the following vulnerability has been resolved: d ...)
CVE-2026-89818
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn: fix integer overflow in dec_msg buffer count check If the supplied msg[2] (num_buffers) is 0x3FFFFFFF, the expression 6 + num_buffers * 4 wraps to 2 and the bounds check passes, letting the parser loop far past the end of the message BO. Triggering it additionally requires a ~4GiB mapping so that msg[1] survives the earlier "header does not fit in BO" check. Rewrite the test in division form, which is overflow-free by construction. Also update the message to reflect that msg is invalid.
CVE-2026-89818
drm/amdgpu/vcn: fix integer overflow in dec_msg buffer count check
CVE-2026-89818
In the Linux kernel, the following vulnerability has been resolved: d ...
GHSA-vg7q-4fvq-5g86
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn: fix integer overflow in dec_msg buffer count check If the supplied msg[2] (num_buffers) is 0x3FFFFFFF, the expression 6 + num_buffers * 4 wraps to 2 and the bounds check passes, letting the parser loop far past the end of the message BO. Triggering it additionally requires a ~4GiB mapping so that msg[1] survives the earlier "header does not fit in BO" check. Rewrite the test in division form, which is overflow-free by construction. Also update the message to reflect that msg is invalid.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-89818 (In the Linux kernel, the following vulnerability has been resolved: d ...) | CVSS3: 7.1 | 0% Низкий | 6 дней назад | |
CVE-2026-89818 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn: fix integer overflow in dec_msg buffer count check If the supplied msg[2] (num_buffers) is 0x3FFFFFFF, the expression 6 + num_buffers * 4 wraps to 2 and the bounds check passes, letting the parser loop far past the end of the message BO. Triggering it additionally requires a ~4GiB mapping so that msg[1] survives the earlier "header does not fit in BO" check. Rewrite the test in division form, which is overflow-free by construction. Also update the message to reflect that msg is invalid. | CVSS3: 7.1 | 0% Низкий | 6 дней назад | |
CVE-2026-89818 drm/amdgpu/vcn: fix integer overflow in dec_msg buffer count check | 0% Низкий | 5 дней назад | ||
CVE-2026-89818 In the Linux kernel, the following vulnerability has been resolved: d ... | CVSS3: 7.1 | 0% Низкий | 6 дней назад | |
GHSA-vg7q-4fvq-5g86 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn: fix integer overflow in dec_msg buffer count check If the supplied msg[2] (num_buffers) is 0x3FFFFFFF, the expression 6 + num_buffers * 4 wraps to 2 and the bounds check passes, letting the parser loop far past the end of the message BO. Triggering it additionally requires a ~4GiB mapping so that msg[1] survives the earlier "header does not fit in BO" check. Rewrite the test in division form, which is overflow-free by construction. Also update the message to reflect that msg is invalid. | CVSS3: 7.1 | 0% Низкий | 6 дней назад |
Уязвимостей на страницу