CVE-2026-23468: drm/amdgpu: Limit BO list entry count to prevent resource exhaustion

Published Apr 3, 2026
·
Updated

drm/amdgpu: Limit BO list entry count to prevent resource exhaustion

Affected Software

10 affected componentsFixes available
Linux Linux kernel (drm/amdgpu)
Linux Linux kernel>=4.2<6.6.140
Linux Linux kernel>=6.7<6.12.86
Linux Linux kernel>=6.13<6.18.20
Linux Linux kernel>=6.19<6.19.10
Linux Linux kernel=7.0-rc1
Linux Linux kernel=7.0-rc2
Linux Linux kernel=7.0-rc3
Linux Linux kernel=7.0-rc4
Microsoft azl3 kernel 6.6.139.1-1<6.6.141.1-1
6.6.141.1-1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 6.6.141.1-1
  2. Configuration

    Introduce a hard limit of 128k entries per BO list in the drm/amdgpu BO list handling, and make the code return -EINVAL if the requested entry count exceeds the limit (via the bo_number field) to prevent memory/resource exhaustion.

    Linux kernel (drm/amdgpu) BO list entry count limit (128k) = 128k entries maximum; return -EINVAL when bo_number exceeds 128k

Event History

Apr 3, 2026
CVE Published
via MITRE·03:15 PM
Data Sourced
via MITRE·03:15 PM
Description
Data Sourced
via NVD·04:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Apr 5, 2026
Data Sourced
via Microsoft·08:02 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:02 AM
Affected Software
Updated
via Microsoft·08:02 AM
DescriptionSeverity

Frequently Asked Questions

1

What is the severity of CVE-2026-23468?

CVE-2026-23468 has a medium severity rating of 5.5 based on the CVSS 3.1 scoring.

2

How do I fix CVE-2026-23468?

To mitigate CVE-2026-23468, users should update their Linux kernel and the associated drm/amdgpu driver to the patched versions.

3

What type of vulnerability is CVE-2026-23468?

CVE-2026-23468 is a resource exhaustion vulnerability that can be exploited through the bo_number field.

4

Which systems are affected by CVE-2026-23468?

CVE-2026-23468 affects systems running the Linux kernel and the drm/amdgpu module.

5

What impact does CVE-2026-23468 have on users?

The impact of CVE-2026-23468 could lead to a denial of service due to resource exhaustion.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203