CVE-2026-46230
drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg
Description
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg Check bounds against the end of the BO whenever we access the msg.
INFO
Published Date :
May 28, 2026, 10:16 a.m.
Last Modified :
June 10, 2026, 9:12 p.m.
Remotely Exploit :
No
Source :
416baaa9-dc9f-4396-8d5f-8c081fb06d67
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS 3.1 | HIGH | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
Solution
- Update the Linux kernel to the latest version.
- Verify kernel security patches are applied.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2026-46230.
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2026-46230 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2026-46230
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-46230 vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2026-46230 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
Initial Analysis by [email protected]
Jun. 10, 2026
Action Type Old Value New Value Added CWE CWE-125 Added CPE Configuration OR *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.13 up to (excluding) 5.15.209 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.16 up to (excluding) 6.1.175 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.2 up to (excluding) 6.6.140 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.13 up to (excluding) 6.18.32 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.7 up to (excluding) 6.12.90 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.19 up to (excluding) 7.0.9 Added Reference Type kernel.org: https://git.kernel.org/stable/c/638d3e0b9eb77aa53fdd60e2b928761d16ba76fa Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/638e48ee39d0f2af9336f917a6f5d6692dd64d93 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/82c535eff05490c71153af57de9fe85502fcb5d5 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/870c8738c3774336baedddd0240951d078a703b8 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/b193019860d61e92da395eae2011f2f6716b182f Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/e382e0b81a3e7bd21504fee1d01ae8b08f84d3a7 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/f55552adb100eb54a6e6dabff4fbdc8679bd3fa0 Types: Patch -
CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Jun. 01, 2026
Action Type Old Value New Value Added Reference https://git.kernel.org/stable/c/82c535eff05490c71153af57de9fe85502fcb5d5 Added Reference https://git.kernel.org/stable/c/f55552adb100eb54a6e6dabff4fbdc8679bd3fa0 -
CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
May. 30, 2026
Action Type Old Value New Value Added CVSS V3.1 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H -
New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
May. 28, 2026
Action Type Old Value New Value Added Description In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg Check bounds against the end of the BO whenever we access the msg. Added Reference https://git.kernel.org/stable/c/638d3e0b9eb77aa53fdd60e2b928761d16ba76fa Added Reference https://git.kernel.org/stable/c/638e48ee39d0f2af9336f917a6f5d6692dd64d93 Added Reference https://git.kernel.org/stable/c/870c8738c3774336baedddd0240951d078a703b8 Added Reference https://git.kernel.org/stable/c/b193019860d61e92da395eae2011f2f6716b182f Added Reference https://git.kernel.org/stable/c/e382e0b81a3e7bd21504fee1d01ae8b08f84d3a7