CVE-2026-68276: drm/amdgpu/gfx: fix cleaner shader IB buffer overflow
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/gfx: fix cleaner shader IB buffer overflow
The cleaner shader sysfs path allocates a 16-dword (64 byte) IB but incorrectly fills (alignmask + 1) dwords. On GFX rings alignmask is 0xff, so the loop wrote 256 dwords into a 64-byte buffer, causing a kernel page fault.
The IB only needs to be a minimal NOP shell to schedule the job; the cleaner shader itself is emitted on the ring via emitcleanershader(). Fill 16 dwords to match the allocation.
v2: Use ibsizedw variable (Lijo)
(cherry picked from commit bf21af331ebf72d0935fd70c73192414a422c03a)
Event History
Frequently Asked Questions
What is the severity of CVE-2026-68276?
The severity of CVE-2026-68276 is rated as a risk level of 46.
What type of vulnerability is CVE-2026-68276?
CVE-2026-68276 is classified as a buffer overflow vulnerability.
How does CVE-2026-68276 affect the Linux kernel?
CVE-2026-68276 affects the Linux kernel by allowing a buffer overflow in the cleaner shader IB, which can lead to undefined behavior.
How do I fix CVE-2026-68276?
To fix CVE-2026-68276, update your Linux kernel to the latest version where this vulnerability has been patched.
What systems are impacted by CVE-2026-68276?
CVE-2026-68276 impacts systems running the affected versions of the Linux kernel that utilize the amdgpu graphics drivers.