0.0
NA
CVE-2026-68272
drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1
Description

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1 Add a minimum-length check for the AMDGPU_CHUNK_ID_CP_GFX_SHADOW chunk in amdgpu_cs_pass1(), matching the gate already present for the IB, FENCE and BO_HANDLES chunk types. The CP_GFX_SHADOW case previously shared a bare break with the dependency and syncobj chunk types, which do not dereference a fixed-size struct. When userspace submits this chunk with length_dw == 0, vmemdup_array_user() is called with size 0 and returns ZERO_SIZE_PTR, which passes the IS_ERR() check. amdgpu_cs_p2_shadow() then dereferences chunk->kdata as a struct drm_amdgpu_cs_chunk_cp_gfx_shadow (reading shadow->flags), faulting on the ZERO_SIZE_PTR and causing a NULL-pointer dereference. This is reachable by an unprivileged process in the render group. Reject undersized chunks with -EINVAL during pass1 so the bad submission is rejected before pass2 ever dereferences the data. (cherry picked from commit 7f61b2eef7415eccdb40850aca0de94211948657)

INFO

Published Date :

Aug. 10, 2026, 1:20 p.m.

Last Modified :

Aug. 17, 2026, 5:18 a.m.

Remotely Exploit :

No

Source :

416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Products

The following products are affected by CVE-2026-68272 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Linux linux_kernel
Solution
Apply kernel patches to validate chunk sizes, preventing null pointer dereferences.
  • Update the Linux kernel to the patched version.
  • Ensure minimum chunk size checks are enforced.
  • Validate chunk data structures during processing.
  • Reject undersized chunks with an error.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-68272 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-68272 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-68272 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2026-68272 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Aug. 17, 2026

    Action Type Old Value New Value
    Changed Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': 'ac9287055ff16a092416c76a19006764e4c6a978', 'lessThan': '3f190956404da55560056ce20606010e18bc059c', 'versionType': 'git'}, {'status': 'affected', 'version': 'ac9287055ff16a092416c76a19006764e4c6a978', 'lessThan': '2aa9ea2bd5146d237c8cc16d8737d878b0298a94', 'versionType': 'git'}, {'status': 'affected', 'version': 'ac9287055ff16a092416c76a19006764e4c6a978', 'lessThan': '315d2e5741a81b0be763e80413a2677e22b7e596', 'versionType': 'git'}, {'status': 'affected', 'version': 'ac9287055ff16a092416c76a19006764e4c6a978', 'lessThan': '24668ca3ec19434d7a9574bf9112f2b0614c3a4e', 'versionType': 'git'}, {'status': 'affected', 'version': 'ac9287055ff16a092416c76a19006764e4c6a978', 'lessThan': '84c4c36acd5c4b2558b5069f869a165b2c655c84', 'versionType': 'git'}], 'programFiles': ['drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '6.5'}, {'status': 'unaffected', 'version': '0', 'lessThan': '6.5', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.6.148', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.101', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.42', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.6', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c'], 'defaultStatus': 'affected'}] [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': 'ac9287055ff16a092416c76a19006764e4c6a978', 'lessThan': '3f190956404da55560056ce20606010e18bc059c', 'versionType': 'git'}, {'status': 'affected', 'version': 'ac9287055ff16a092416c76a19006764e4c6a978', 'lessThan': '2aa9ea2bd5146d237c8cc16d8737d878b0298a94', 'versionType': 'git'}, {'status': 'affected', 'version': 'ac9287055ff16a092416c76a19006764e4c6a978', 'lessThan': '315d2e5741a81b0be763e80413a2677e22b7e596', 'versionType': 'git'}, {'status': 'affected', 'version': 'ac9287055ff16a092416c76a19006764e4c6a978', 'lessThan': '24668ca3ec19434d7a9574bf9112f2b0614c3a4e', 'versionType': 'git'}, {'status': 'affected', 'version': 'ac9287055ff16a092416c76a19006764e4c6a978', 'lessThan': '84c4c36acd5c4b2558b5069f869a165b2c655c84', 'versionType': 'git'}], 'programFiles': ['drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '6.5'}, {'status': 'unaffected', 'version': '0', 'lessThan': '6.5', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.6.148', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.101', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.42', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.6', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c'], 'defaultStatus': 'affected'}]
  • New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Aug. 10, 2026

    Action Type Old Value New Value
    Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': 'ac9287055ff16a092416c76a19006764e4c6a978', 'lessThan': '3f190956404da55560056ce20606010e18bc059c', 'versionType': 'git'}, {'status': 'affected', 'version': 'ac9287055ff16a092416c76a19006764e4c6a978', 'lessThan': '2aa9ea2bd5146d237c8cc16d8737d878b0298a94', 'versionType': 'git'}, {'status': 'affected', 'version': 'ac9287055ff16a092416c76a19006764e4c6a978', 'lessThan': '315d2e5741a81b0be763e80413a2677e22b7e596', 'versionType': 'git'}, {'status': 'affected', 'version': 'ac9287055ff16a092416c76a19006764e4c6a978', 'lessThan': '24668ca3ec19434d7a9574bf9112f2b0614c3a4e', 'versionType': 'git'}, {'status': 'affected', 'version': 'ac9287055ff16a092416c76a19006764e4c6a978', 'lessThan': '84c4c36acd5c4b2558b5069f869a165b2c655c84', 'versionType': 'git'}], 'programFiles': ['drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '6.5'}, {'status': 'unaffected', 'version': '0', 'lessThan': '6.5', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.6.148', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.101', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.42', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.6', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c'], 'defaultStatus': 'affected'}]
    Added Description In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1 Add a minimum-length check for the AMDGPU_CHUNK_ID_CP_GFX_SHADOW chunk in amdgpu_cs_pass1(), matching the gate already present for the IB, FENCE and BO_HANDLES chunk types. The CP_GFX_SHADOW case previously shared a bare break with the dependency and syncobj chunk types, which do not dereference a fixed-size struct. When userspace submits this chunk with length_dw == 0, vmemdup_array_user() is called with size 0 and returns ZERO_SIZE_PTR, which passes the IS_ERR() check. amdgpu_cs_p2_shadow() then dereferences chunk->kdata as a struct drm_amdgpu_cs_chunk_cp_gfx_shadow (reading shadow->flags), faulting on the ZERO_SIZE_PTR and causing a NULL-pointer dereference. This is reachable by an unprivileged process in the render group. Reject undersized chunks with -EINVAL during pass1 so the bad submission is rejected before pass2 ever dereferences the data. (cherry picked from commit 7f61b2eef7415eccdb40850aca0de94211948657)
    Added Reference https://git.kernel.org/stable/c/24668ca3ec19434d7a9574bf9112f2b0614c3a4e
    Added Reference https://git.kernel.org/stable/c/2aa9ea2bd5146d237c8cc16d8737d878b0298a94
    Added Reference https://git.kernel.org/stable/c/315d2e5741a81b0be763e80413a2677e22b7e596
    Added Reference https://git.kernel.org/stable/c/3f190956404da55560056ce20606010e18bc059c
    Added Reference https://git.kernel.org/stable/c/84c4c36acd5c4b2558b5069f869a165b2c655c84
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.