Linux Kernel UVD Message Handling Vulnerability in AMD Graphics
CVE-2026-80909

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-80909?

A flaw in the Linux kernel's AMD GPU driver (drm/amdgpu) allows improper handling of UVD messages with an invalid number of H.265 reference frames. This can lead to potential overflow situations during the calculation of the minimum decoded picture buffer size, creating risks in system reliability and performance. The issue has been addressed to ensure that invalid UVD messages are effectively rejected, providing enhanced protection against overflow vulnerabilities.

Affected Version(s)

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 1facad2a78c1a8aeecc36eb4d560c7f1e10ce198

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 499907e5d46e575e96967c0230a0a6af980a17ab

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.