CVE-2026-23468

ANALYSIS PENDING

drm/amdgpu: Limit BO list entry count to prevent resource exhaustion

Title source: cna
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Limit BO list entry count to prevent resource exhaustion Userspace can pass an arbitrary number of BO list entries via the bo_number field. Although the previous multiplication overflow check prevents out-of-bounds allocation, a large number of entries could still cause excessive memory allocation (up to potentially gigabytes) and unnecessarily long list processing times. Introduce a hard limit of 128k entries per BO list, which is more than sufficient for any realistic use case (e.g., a single list containing all buffers in a large scene). This prevents memory exhaustion attacks and ensures predictable performance. Return -EINVAL if the requested entry count exceeds the limit (cherry picked from commit 688b87d39e0aa8135105b40dc167d74b5ada5332)

Scores

EPSS 0.0004
EPSS Percentile 13.9%

Details

Status published
Products (16)
Linux/Linux < 4.2
Linux/Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - 5ce4a38e6c2488949e373d5066303f9c128db614
Linux/Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - 6270b1a5dab94665d7adce3dc78bc9066ed28bdd
Linux/Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - f462624a6e4b5f1ec2664c2c53e408b2f4fb53e9
Linux/Linux 4.2
Linux/Linux 6.12.86 - 6.12.*
Linux/Linux 6.18.20 - 6.18.*
Linux/Linux 6.19.10 - 6.19.*
Linux/Linux 6.6.140 - 6.6.*
Linux/Linux 7.0
... and 6 more
Published Apr 03, 2026
Tracked Since Apr 03, 2026