CVE-2026-46218: drm/amdgpu: Add bounds checking to ib_{get,set}_value
Published May 28, 2026
·Updated
drm/amdgpu: Add bounds checking to ib{get,set}value
Affected Software
7 affected componentsFixes available
Linux Linux kernel (drm/amdgpu)
Linux Linux kernel>=4.2<6.1.175
Linux Linux kernel>=6.2<6.6.140
Linux Linux kernel>=6.7<6.12.90
Linux Linux kernel>=6.13<6.18.32
Linux Linux kernel>=6.19<7.0.9
Microsoft azl3 kernel 6.6.139.1-1<6.6.141.1-1
6.6.141.1-1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.141.1-1
Event History
May 28, 2026
CVE Published
via MITRE·09:40 AM
Data Sourced
via MITRE·09:40 AM
DescriptionSeverity
Data Sourced
via NVD·10:16 AM
RemedyDescriptionSeverityAffected Software
May 29, 2026
Data Sourced
via Microsoft·08:06 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:06 AM
Affected Software
Updated
via Microsoft·08:06 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2026-46218?
The severity of CVE-2026-46218 is rated as high, with a score of 7.1.
2
How do I fix CVE-2026-46218?
Fixing CVE-2026-46218 involves updating the Linux kernel to a version where bounds checking has been implemented for ib_{get,set}_value.
3
What are the risks associated with CVE-2026-46218?
CVE-2026-46218 poses a risk of potential information disclosure and denial of service due to improper bounds checking in the Linux kernel.
4
In which software is CVE-2026-46218 found?
CVE-2026-46218 is found in the Linux kernel, specifically in the drm/amdgpu component.
5
What components are affected by CVE-2026-46218?
The affected components of CVE-2026-46218 include the uvd, vce, and vcn code within the Linux kernel's drm/amdgpu.