CVE-2026-68108: drm/amdgpu/vce: fix integer overflow in image size
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/vce: fix integer overflow in image size
Fix a security vulnerability where malicious VCE command streams with oversized dimensions (e.g. 65536×65536) cause 32-bit integer overflow, wrapping the calculated buffer size to 0. This bypasses validation and allows GPU firmware to perform out-of-bound memory access.
The fix uses 64-bit arithmetic to detect overflow and rejects invalid dimensions before they reach the hardware.
V2: remove redundant check V3: modify max height value V4: remove size64
(cherry picked from commit cbe408dba581755ad1279a487ec786d8927d778d)
Event History
Frequently Asked Questions
What is the severity of CVE-2026-68108?
The severity of CVE-2026-68108 is rated as risk 48.
How do I fix CVE-2026-68108?
To fix CVE-2026-68108, update the Linux kernel to the latest version that resolves this integer overflow issue.
What type of vulnerability is CVE-2026-68108?
CVE-2026-68108 is classified as an integer overflow vulnerability.
What is affected by CVE-2026-68108?
CVE-2026-68108 affects the AMD GPU driver within the Linux kernel.
What can be exploited in CVE-2026-68108?
CVE-2026-68108 can be exploited through malicious VCE command streams that contain oversized image dimensions.