{"apiVersion":"1.0","identifier":"CVE-2026-80576","description":"In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: reject oversized IBs with per-ring packet limits On GFX rings, amdgpu_cs_p2_ib() passed user-supplied ib_bytes through to ib->length_dw without a limit, while ring_emit_ib() encodes length into packet fields. Oversized values can corrupt adjacent control bits and destabilize command submission. Add a per-ring IB packet size limit helper and reject command submissions exceeding the corresponding dword limit before IB allocation. Use the documented 20-bit limit for GFX/compute/SDMA/VPE, and apply the MM fallback limit for other ring types. (cherry picked from commit 7f48fa2cf62e3fa6c9c3870aa74988f773247e52)","publishedAt":"2026-08-26T15:17:13","lastModifiedAt":"2026-08-27T06:17:43","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-80576","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","epssProbability":0.0012,"riskScore":0.89,"affectedProduct":"Linux kernel","affectedVersions":"unknown","vulnerabilityType":"Kernel","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-80576","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-80576","en":"https://www.redsauce.net/en/cves/CVE-2026-80576","fr":"https://www.redsauce.net/fr/cves/CVE-2026-80576","pt":"https://www.redsauce.net/pt/cves/CVE-2026-80576","de":"https://www.redsauce.net/de/cves/CVE-2026-80576","sk":"https://www.redsauce.net/sk/cves/CVE-2026-80576","el":"https://www.redsauce.net/el/cves/CVE-2026-80576"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-80576"}}