CVE-2026-68106 PUBLISHED

drm/amdgpu: fix division by zero with invalid uvd dimensions

Assigner: Linux
Reserved: 30.07.2026 Published: 10.08.2026 Updated: 10.08.2026

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu: fix division by zero with invalid uvd dimensions

When width or height is less than 16, width_in_mb or height_in_mb becomes 0, leading to fs_in_mb being 0. This causes a division by zero when calculating num_dpb_buffer in H264 and H264 Perf decode paths.

Add validation to reject frames with width < 16 or height < 16 before performing any calculations that depend on these values.

V2: Format change - move up all vaiable definitions. V3: Use warn_once to avoid spam.

(cherry picked from commit 3e41d26c70b0a459d041cc19482a226c4b7423cb)

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to 52f9a588296432accf2982f7d258192a37562f4f (excl.)
  • affected from 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to a00946b5ab7c25da5685ca9c58f50ff6f43c0fdf (excl.)
  • affected from 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to ffb33d466a68cea3e8a3dbed04d79037a3cbabd1 (excl.)
  • affected from 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to be725ab23aa45c11a5afef3e2a9f6d8c084ae5dc (excl.)
  • affected from 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to 0c01c811be47e6b146552dd59bfedbea8f09b8f4 (excl.)
  • affected from 0 to 6.6.148 (excl.)
  • affected from 0 to 6.12.101 (excl.)
  • affected from 0 to 6.18.42 (excl.)
  • affected from 0 to 7.1.6 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • unaffected from 6.6.148 to 6.6.* (incl.)
  • unaffected from 6.12.101 to 6.12.* (incl.)
  • unaffected from 6.18.42 to 6.18.* (incl.)
  • unaffected from 7.1.6 to 7.1.* (incl.)
  • unaffected from 7.2-rc2 to * (incl.)

References