5.5
MEDIUM CVSS 3.1
CVE-2026-46217
drm/amdgpu/vcn4: Avoid overflow on msg bound check
Description

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

INFO

Published Date :

May 28, 2026, 10:16 a.m.

Last Modified :

June 15, 2026, 10:16 a.m.

Remotely Exploit :

No

Source :

416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Products

The following products are affected by CVE-2026-46217 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Linux linux_kernel
CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 3.1 MEDIUM [email protected]
Solution
Update the Linux kernel to the latest version to fix an overflow vulnerability in the AMDGPU driver.
  • Update the Linux kernel to the latest version.
  • Apply the specific patch for the AMDGPU driver.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-46217 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2026-46217 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • CVE Rejected by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Jun. 15, 2026

    Action Type Old Value New Value
  • CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Jun. 15, 2026

    Action Type Old Value New Value
    Changed Description In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn4: Avoid overflow on msg bound check As pointed out by SDL, the previous condition may be vulnerable to overflow. (cherry picked from commit 3c5367d950140d4ec7af830b2268a5a6fdaa3885) Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
    Removed CVSS V3.1 NIST: AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
    Removed CWE NIST: CWE-674
    Removed CPE Configuration OR *cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
    Removed Reference kernel.org: https://git.kernel.org/stable/c/271cd5429513ff9b364a9bf8903e5b65b687eb25
    Removed Reference kernel.org: https://git.kernel.org/stable/c/30d12ee310a6024ff4c7b9eafdbbeab2db450d4a
    Removed Reference kernel.org: https://git.kernel.org/stable/c/5bb5faff4837b1d98fd655cf8bd7b5d4da0fc4dc
    Removed Reference kernel.org: https://git.kernel.org/stable/c/65bce27ea6192320448c30267ffc17ffa094e713
    Removed Reference kernel.org: https://git.kernel.org/stable/c/73043d296787bf187d89ffb5c5dcf5bdc3db7885
    Removed Reference kernel.org: https://git.kernel.org/stable/c/f7bf02dcb7c76229ea8ace11b7d0d0c7b87ee57e
    Removed Reference Type kernel.org: https://git.kernel.org/stable/c/271cd5429513ff9b364a9bf8903e5b65b687eb25 Types: Patch
    Removed Reference Type kernel.org: https://git.kernel.org/stable/c/30d12ee310a6024ff4c7b9eafdbbeab2db450d4a Types: Patch
    Removed Reference Type kernel.org: https://git.kernel.org/stable/c/5bb5faff4837b1d98fd655cf8bd7b5d4da0fc4dc Types: Patch
    Removed Reference Type kernel.org: https://git.kernel.org/stable/c/65bce27ea6192320448c30267ffc17ffa094e713 Types: Patch
    Removed Reference Type kernel.org: https://git.kernel.org/stable/c/73043d296787bf187d89ffb5c5dcf5bdc3db7885 Types: Patch
    Removed Reference Type kernel.org: https://git.kernel.org/stable/c/f7bf02dcb7c76229ea8ace11b7d0d0c7b87ee57e Types: Patch
  • Initial Analysis by [email protected]

    Jun. 10, 2026

    Action Type Old Value New Value
    Added CVSS V3.1 AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
    Added CWE CWE-674
    Added CPE Configuration OR *cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/271cd5429513ff9b364a9bf8903e5b65b687eb25 Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/30d12ee310a6024ff4c7b9eafdbbeab2db450d4a Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/5bb5faff4837b1d98fd655cf8bd7b5d4da0fc4dc Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/65bce27ea6192320448c30267ffc17ffa094e713 Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/73043d296787bf187d89ffb5c5dcf5bdc3db7885 Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/f7bf02dcb7c76229ea8ace11b7d0d0c7b87ee57e Types: Patch
  • CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Jun. 01, 2026

    Action Type Old Value New Value
    Added Reference https://git.kernel.org/stable/c/f7bf02dcb7c76229ea8ace11b7d0d0c7b87ee57e
  • New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    May. 28, 2026

    Action Type Old Value New Value
    Added Description In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn4: Avoid overflow on msg bound check As pointed out by SDL, the previous condition may be vulnerable to overflow. (cherry picked from commit 3c5367d950140d4ec7af830b2268a5a6fdaa3885)
    Added Reference https://git.kernel.org/stable/c/271cd5429513ff9b364a9bf8903e5b65b687eb25
    Added Reference https://git.kernel.org/stable/c/30d12ee310a6024ff4c7b9eafdbbeab2db450d4a
    Added Reference https://git.kernel.org/stable/c/5bb5faff4837b1d98fd655cf8bd7b5d4da0fc4dc
    Added Reference https://git.kernel.org/stable/c/65bce27ea6192320448c30267ffc17ffa094e713
    Added Reference https://git.kernel.org/stable/c/73043d296787bf187d89ffb5c5dcf5bdc3db7885
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.