{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-68107","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-07-30T09:28:09.368Z","datePublished":"2026-08-10T11:58:24.135Z","dateUpdated":"2026-08-17T04:58:56.350Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-17T04:58:56.350Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/vcn4: avoid rereading IB param length\n\nReuse the parameter length returned by\nvcn_v4_0_enc_find_ib_param() instead of rereading it from\nthe IB.\n\nThis avoids a potential TOCTOU issue if the IB contents\nchange between reads.\n\n(cherry picked from commit dbb02b4755f8c1f3773263f2d779872c1c0c073a)"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The flaw is only reachable through the local AMDGPU_CS DRM ioctl on /dev/dri/renderD* (amdgpu_cs_ioctl → amdgpu_cs_patch_jobs → amdgpu_cs_patch_ibs), which kmaps the user IB and calls vcn_v4_0_ring_patch_cs_in_place(); no network or physical-device path exists.\nAC:L - patch_cs_in_place reads IB contents directly from attacker-mapped GEM memory without copying; a concurrent thread can change the param-length dword between vcn_v4_0_enc_find_ib_param()'s initial read and the later idx+=amdgpu_ib_get_value(ib,idx)/4, so the attacker controls both sides of the TOCTOU race.\nPR:L - AMDGPU_CS is registered with DRM_AUTH|DRM_RENDER_ALLOW, so any local user who can open the AMDGPU render node (typical render/video group on desktops, gaming handhelds, and GPU cloud instances) can submit VCN4 command buffers without root or init-namespace capabilities.\nUI:N - Exploitation requires only the attacker submitting crafted VCN encode IBs through their own DRM context; no separate victim action such as opening a file, mounting a filesystem, or interacting with malicious content is needed.\nS:C - On VFIO GPU-passthrough and cloud ML hosts, a malicious VM guest submits VCN command streams through the assigned AMD GPU to corrupt host amdgpu kernel state, crossing the guest-to-hypervisor security boundary analogous to a device-model escape.\nC:H - Racing the length dword smaller under-advances IB iteration so nested RADEON_VCN_ENGINE_INFO entries inside a parent package are reached; vcn_v4_0_dec_msg() then reads user-mapped message buffers without snapshotting, enabling TOCTOU check/use mismatches on length/offset fields and out-of-bounds kernel reads past validated bounds.\nI:H - The same nested-entry bypass plus unsnapshotted dec_msg parsing lets userspace rewrite offset/size after kernel validation, driving out-of-bounds accesses in the message loop; skipping vcn_v4_0_limit_sched() via mis-iteration also leaves scheduler/BO state inconsistently modified in attacker-influenceable ways.\nA:H - Racing the length field to zero on re-read makes idx+=0 and re-enters the same ENGINE_INFO entry indefinitely, soft-locking the CS ioctl path; vcn_v4_0_limit_sched() may also block in dma_fence_wait(), yielding repeatable kernel denial-of-service on shared GPU hosts."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/gpu/drm/amd/amdgpu/vcn_v4_0.c"],"versions":[{"version":"cfdde9197ecd957281507be99af172671a57755c","lessThan":"bbbe6a2a8d8dc87243438d3ffea2083b52d882d9","status":"affected","versionType":"git"},{"version":"6dc4eddeb7e6cca7e1ab32cafbda79d06e652d84","lessThan":"ff6aa542d91d76a185f69bd1997b94a560ff5f6b","status":"affected","versionType":"git"},{"version":"2b10cb58d7a3fd621ec9b2ba765a092e562ef998","lessThan":"bd868c077f67589ed2a714307ceaade5f246e302","status":"affected","versionType":"git"},{"version":"2b10cb58d7a3fd621ec9b2ba765a092e562ef998","lessThan":"c309626bf91fa0a0b583575654e6e14e81f818a3","status":"affected","versionType":"git"},{"version":"2b10cb58d7a3fd621ec9b2ba765a092e562ef998","lessThan":"3b4082fabc67c9780b06eb959e59dd92fa79c0f0","status":"affected","versionType":"git"},{"version":"b1dc92f55b22a80ded8f0263c9ef4ba902303895","status":"affected","versionType":"git"},{"version":"6.6.107","lessThan":"6.6.148","status":"affected","versionType":"semver"},{"version":"6.12.48","lessThan":"6.12.101","status":"affected","versionType":"semver"},{"version":"6.16.8","lessThan":"6.17","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/gpu/drm/amd/amdgpu/vcn_v4_0.c"],"versions":[{"version":"6.17","status":"affected"},{"version":"0","lessThan":"6.17","status":"unaffected","versionType":"semver"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6.107","versionEndExcluding":"6.6.148"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.12.48","versionEndExcluding":"6.12.101"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.17","versionEndExcluding":"6.18.42"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.17","versionEndExcluding":"7.1.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.17","versionEndExcluding":"7.2"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.16.8"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/bbbe6a2a8d8dc87243438d3ffea2083b52d882d9"},{"url":"https://git.kernel.org/stable/c/ff6aa542d91d76a185f69bd1997b94a560ff5f6b"},{"url":"https://git.kernel.org/stable/c/bd868c077f67589ed2a714307ceaade5f246e302"},{"url":"https://git.kernel.org/stable/c/c309626bf91fa0a0b583575654e6e14e81f818a3"},{"url":"https://git.kernel.org/stable/c/3b4082fabc67c9780b06eb959e59dd92fa79c0f0"}],"title":"drm/amdgpu/vcn4: avoid rereading IB param length","x_generator":{"engine":"bippy-1.2.0"}}}}