CVE-2026-68276 PUBLISHED

drm/amdgpu/gfx: fix cleaner shader IB buffer overflow

Assigner: Linux
Reserved: 30.07.2026 Published: 10.08.2026 Updated: 10.08.2026

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu/gfx: fix cleaner shader IB buffer overflow

The cleaner shader sysfs path allocates a 16-dword (64 byte) IB but incorrectly fills (align_mask + 1) dwords. On GFX rings align_mask is 0xff, so the loop wrote 256 dwords into a 64-byte buffer, causing a kernel page fault.

The IB only needs to be a minimal NOP shell to schedule the job; the cleaner shader itself is emitted on the ring via emit_cleaner_shader(). Fill 16 dwords to match the allocation.

v2: Use ib_size_dw variable (Lijo)

(cherry picked from commit bf21af331ebf72d0935fd70c73192414a422c03a)

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from d361ad5d2fc0e4d59d5d538092c9b37889756642 to 201633f47b542a99bb7baafdfcda7781249fb3d9 (excl.)
  • affected from d361ad5d2fc0e4d59d5d538092c9b37889756642 to e28420e36542ae8b66a5bdcec419525f521bddf8 (excl.)
  • affected from d361ad5d2fc0e4d59d5d538092c9b37889756642 to 9cd9a983769a4d0e9cc80a287316ee79685d38b3 (excl.)
  • affected from d361ad5d2fc0e4d59d5d538092c9b37889756642 to 3e864bf2a32a1cbdf1e0f9c5a5a4176e8575f4a3 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.12 is affected
  • unaffected from 0 to 6.12 (excl.)
  • unaffected from 6.12.103 to 6.12.* (incl.)
  • unaffected from 6.18.42 to 6.18.* (incl.)
  • unaffected from 7.1.6 to 7.1.* (incl.)
  • unaffected from 7.2-rc1 to * (incl.)

References