Description
In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu/vce: Prevent partial address patches

In the case that only one of lo/hi is valid, the patching could result
in a bad address written to in FW.
Published: 2026-07-19
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Linux kernel contains an out‑of‑bounds write flaw in the AMDGPU Video Code Engine driver caused by partial address patches. When only the low or high half of an address is validated during firmware patching, the driver writes an invalid address into the firmware image. This corruption can compromise firmware integrity and potentially lead to uncontrolled memory writes if the malformed firmware is later executed, presenting a severe integrity risk. The weakness is identified as CWE‑787, a classic out‑of‑bounds write vulnerability.

Affected Systems

The flaw affects all Linux kernel builds that include the AMDGPU VCE component without the recent patch. As the CNA does not list specific kernel version numbers, it is inferred that any older kernel that ships with the vulnerable driver is susceptible. Systems running newer kernels that have incorporated the fix are not impacted.

Risk and Exploitability

With a CVSS score of 8.8, the vulnerability is classified as high‑severity. The EPSS score of less than 1 % indicates a very low current exploitation likelihood, and the flaw is not part of CISA’s KEV catalog. Exploitation would likely require local or kernel‑privileged access to manipulate firmware addressing, and no publicly available exploit has been reported. The risk remains high until the kernel is updated to a patched release. The likely attack vector is inferred as local or kernel‑privileged, because writing to firmware requires such privileges, but this is not explicitly stated in the input.

Generated by OpenCVE AI on July 30, 2026 at 22:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to a kernel release that includes the AMDGPU VCE patch
  • If an immediate kernel update is not possible, recompile the kernel with AMDGPU VCE support disabled (CONFIG_DRM_AMD_VCE=n) to eliminate the faulty address patching
  • Apply any vendor‑supplied firmware updates that address partial address handling

Generated by OpenCVE AI on July 30, 2026 at 22:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Ubuntu USN Ubuntu USN USN-8574-1 Linux kernel (GCP FIPS) vulnerabilities
Ubuntu USN Ubuntu USN USN-8593-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8574-2 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8595-1 Linux kernel (Oracle) vulnerabilities
Ubuntu USN Ubuntu USN USN-8596-1 Linux kernel (NVIDIA) vulnerabilities
Ubuntu USN Ubuntu USN USN-8595-2 Linux kernel (AWS) vulnerabilities
Ubuntu USN Ubuntu USN USN-8603-1 Linux kernel (Azure) vulnerabilities
Ubuntu USN Ubuntu USN USN-8606-1 Linux kernel (Azure) vulnerabilities
Ubuntu USN Ubuntu USN USN-8607-1 Linux kernel (Azure CVM) vulnerabilities
Ubuntu USN Ubuntu USN USN-8608-1 Linux kernel (Azure FIPS) vulnerabilities
Ubuntu USN Ubuntu USN USN-8609-1 Linux kernel (Azure CVM) vulnerabilities
Ubuntu USN Ubuntu USN USN-8574-3 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8595-3 Linux kernel (AWS) vulnerabilities
Ubuntu USN Ubuntu USN USN-8618-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8619-1 Linux kernel (HWE) vulnerabilities
History

Tue, 21 Jul 2026 00:15:00 +0000


Mon, 20 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Sun, 19 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vce: Prevent partial address patches In the case that only one of lo/hi is valid, the patching could result in a bad address written to in FW.
Title drm/amdgpu/vce: Prevent partial address patches
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-05T12:35:19.662Z

Reserved: 2026-06-09T07:44:35.401Z

Link: CVE-2026-53375

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

Severity :

Publid Date: 2026-07-19T00:00:00Z

Links: CVE-2026-53375 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T22:45:04Z

Weaknesses