Description
In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu: Fix UVD decode image min size calculation

This needs to use pitch instead of width. Also reject pitch
over 4096 to avoid overflow.

(cherry picked from commit b41c8cb12e202b220353332ab87dc01a11f69304)
Published: 2026-08-26
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Linux kernel contained a bug in the AMDGPU driver where the minimum size for UVD decode images was calculated using the pitch value instead of the width. This logic error could allow a pitch value exceeding 4096 to cause an integer overflow, potentially leading to a buffer overflow or denial of service. The commit that fixed the issue also adds a rejection for pitches larger than 4096 to prevent the overflow. The vulnerability was addressed before release, and the provided references show the patch implementation.

Affected Systems

All Linux distributions that ship the Linux kernel before the commit that fixed the UVD decode image size calculation are affected. The issue manifests only in environments that use the AMDGPU driver and attempt to decode UVD streams. If a system uses a kernel version that incorporates the commit, the bug is resolved; otherwise any older kernel is vulnerable.

Risk and Exploitability

No CVSS score is reported, and the EPSS is not available, so the risk is unquantified but the flaw is a classic integer overflow leading to a potential memory corruption. The vulnerability was not listed in CISA KEV, indicating no known active exploitation. Based on the description, it is inferred that an attacker could trigger the overflow by sending a video decode request with a pitch greater than 4096, likely requiring local or privileged execution. The impact would be a crash or potential escalated privileges depending on the context of the memory write.

Generated by OpenCVE AI on August 26, 2026 at 15:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the commit fixing the issue as referenced in the Git logs
  • Configure or upgrade the AMDGPU driver so that pitches exceeding 4096 are rejected or constrained, ensuring the safe-path is used for UVD decoding
  • If an immediate kernel or driver update is not possible, disable the UVD hardware decoder or switch to software-based video decoding to avoid the vulnerable code path

Generated by OpenCVE AI on August 26, 2026 at 15:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Wed, 26 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix UVD decode image min size calculation This needs to use pitch instead of width. Also reject pitch over 4096 to avoid overflow. (cherry picked from commit b41c8cb12e202b220353332ab87dc01a11f69304)
Title drm/amdgpu: Fix UVD decode image min size calculation
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-26T14:37:13.966Z

Reserved: 2026-08-26T14:34:25.765Z

Link: CVE-2026-80540

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-26T15:17:08.257

Modified: 2026-08-26T15:17:08.257

Link: CVE-2026-80540

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T18:00:04Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer