CVE-2026-68272

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/08/2026
Last modified:
17/08/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1<br /> <br /> Add a minimum-length check for the AMDGPU_CHUNK_ID_CP_GFX_SHADOW chunk in<br /> amdgpu_cs_pass1(), matching the gate already present for the IB, FENCE and<br /> BO_HANDLES chunk types.<br /> <br /> The CP_GFX_SHADOW case previously shared a bare break with the dependency<br /> and syncobj chunk types, which do not dereference a fixed-size struct. When<br /> userspace submits this chunk with length_dw == 0, vmemdup_array_user() is<br /> called with size 0 and returns ZERO_SIZE_PTR, which passes the IS_ERR()<br /> check. amdgpu_cs_p2_shadow() then dereferences chunk-&gt;kdata as a struct<br /> drm_amdgpu_cs_chunk_cp_gfx_shadow (reading shadow-&gt;flags), faulting on the<br /> ZERO_SIZE_PTR and causing a NULL-pointer dereference.<br /> <br /> This is reachable by an unprivileged process in the render group. Reject<br /> undersized chunks with -EINVAL during pass1 so the bad submission is<br /> rejected before pass2 ever dereferences the data.<br /> <br /> (cherry picked from commit 7f61b2eef7415eccdb40850aca0de94211948657)

Impact