CVE-2026-68272
drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1
Description
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1 Add a minimum-length check for the AMDGPU_CHUNK_ID_CP_GFX_SHADOW chunk in amdgpu_cs_pass1(), matching the gate already present for the IB, FENCE and BO_HANDLES chunk types. The CP_GFX_SHADOW case previously shared a bare break with the dependency and syncobj chunk types, which do not dereference a fixed-size struct. When userspace submits this chunk with length_dw == 0, vmemdup_array_user() is called with size 0 and returns ZERO_SIZE_PTR, which passes the IS_ERR() check. amdgpu_cs_p2_shadow() then dereferences chunk->kdata as a struct drm_amdgpu_cs_chunk_cp_gfx_shadow (reading shadow->flags), faulting on the ZERO_SIZE_PTR and causing a NULL-pointer dereference. This is reachable by an unprivileged process in the render group. Reject undersized chunks with -EINVAL during pass1 so the bad submission is rejected before pass2 ever dereferences the data. (cherry picked from commit 7f61b2eef7415eccdb40850aca0de94211948657)
INFO
Published Date :
Aug. 10, 2026, 1:20 p.m.
Last Modified :
Aug. 17, 2026, 5:18 a.m.
Remotely Exploit :
No
Source :
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Solution
- Update the Linux kernel to the patched version.
- Ensure minimum chunk size checks are enforced.
- Validate chunk data structures during processing.
- Reject undersized chunks with an error.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2026-68272.
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2026-68272 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2026-68272
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-68272 vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2026-68272 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Aug. 17, 2026
Action Type Old Value New Value Changed Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': 'ac9287055ff16a092416c76a19006764e4c6a978', 'lessThan': '3f190956404da55560056ce20606010e18bc059c', 'versionType': 'git'}, {'status': 'affected', 'version': 'ac9287055ff16a092416c76a19006764e4c6a978', 'lessThan': '2aa9ea2bd5146d237c8cc16d8737d878b0298a94', 'versionType': 'git'}, {'status': 'affected', 'version': 'ac9287055ff16a092416c76a19006764e4c6a978', 'lessThan': '315d2e5741a81b0be763e80413a2677e22b7e596', 'versionType': 'git'}, {'status': 'affected', 'version': 'ac9287055ff16a092416c76a19006764e4c6a978', 'lessThan': '24668ca3ec19434d7a9574bf9112f2b0614c3a4e', 'versionType': 'git'}, {'status': 'affected', 'version': 'ac9287055ff16a092416c76a19006764e4c6a978', 'lessThan': '84c4c36acd5c4b2558b5069f869a165b2c655c84', 'versionType': 'git'}], 'programFiles': ['drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '6.5'}, {'status': 'unaffected', 'version': '0', 'lessThan': '6.5', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.6.148', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.101', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.42', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.6', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c'], 'defaultStatus': 'affected'}] [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': 'ac9287055ff16a092416c76a19006764e4c6a978', 'lessThan': '3f190956404da55560056ce20606010e18bc059c', 'versionType': 'git'}, {'status': 'affected', 'version': 'ac9287055ff16a092416c76a19006764e4c6a978', 'lessThan': '2aa9ea2bd5146d237c8cc16d8737d878b0298a94', 'versionType': 'git'}, {'status': 'affected', 'version': 'ac9287055ff16a092416c76a19006764e4c6a978', 'lessThan': '315d2e5741a81b0be763e80413a2677e22b7e596', 'versionType': 'git'}, {'status': 'affected', 'version': 'ac9287055ff16a092416c76a19006764e4c6a978', 'lessThan': '24668ca3ec19434d7a9574bf9112f2b0614c3a4e', 'versionType': 'git'}, {'status': 'affected', 'version': 'ac9287055ff16a092416c76a19006764e4c6a978', 'lessThan': '84c4c36acd5c4b2558b5069f869a165b2c655c84', 'versionType': 'git'}], 'programFiles': ['drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '6.5'}, {'status': 'unaffected', 'version': '0', 'lessThan': '6.5', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.6.148', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.101', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.42', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.6', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c'], 'defaultStatus': 'affected'}] -
New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Aug. 10, 2026
Action Type Old Value New Value Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': 'ac9287055ff16a092416c76a19006764e4c6a978', 'lessThan': '3f190956404da55560056ce20606010e18bc059c', 'versionType': 'git'}, {'status': 'affected', 'version': 'ac9287055ff16a092416c76a19006764e4c6a978', 'lessThan': '2aa9ea2bd5146d237c8cc16d8737d878b0298a94', 'versionType': 'git'}, {'status': 'affected', 'version': 'ac9287055ff16a092416c76a19006764e4c6a978', 'lessThan': '315d2e5741a81b0be763e80413a2677e22b7e596', 'versionType': 'git'}, {'status': 'affected', 'version': 'ac9287055ff16a092416c76a19006764e4c6a978', 'lessThan': '24668ca3ec19434d7a9574bf9112f2b0614c3a4e', 'versionType': 'git'}, {'status': 'affected', 'version': 'ac9287055ff16a092416c76a19006764e4c6a978', 'lessThan': '84c4c36acd5c4b2558b5069f869a165b2c655c84', 'versionType': 'git'}], 'programFiles': ['drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '6.5'}, {'status': 'unaffected', 'version': '0', 'lessThan': '6.5', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.6.148', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.101', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.42', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.6', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c'], 'defaultStatus': 'affected'}] Added Description In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1 Add a minimum-length check for the AMDGPU_CHUNK_ID_CP_GFX_SHADOW chunk in amdgpu_cs_pass1(), matching the gate already present for the IB, FENCE and BO_HANDLES chunk types. The CP_GFX_SHADOW case previously shared a bare break with the dependency and syncobj chunk types, which do not dereference a fixed-size struct. When userspace submits this chunk with length_dw == 0, vmemdup_array_user() is called with size 0 and returns ZERO_SIZE_PTR, which passes the IS_ERR() check. amdgpu_cs_p2_shadow() then dereferences chunk->kdata as a struct drm_amdgpu_cs_chunk_cp_gfx_shadow (reading shadow->flags), faulting on the ZERO_SIZE_PTR and causing a NULL-pointer dereference. This is reachable by an unprivileged process in the render group. Reject undersized chunks with -EINVAL during pass1 so the bad submission is rejected before pass2 ever dereferences the data. (cherry picked from commit 7f61b2eef7415eccdb40850aca0de94211948657) Added Reference https://git.kernel.org/stable/c/24668ca3ec19434d7a9574bf9112f2b0614c3a4e Added Reference https://git.kernel.org/stable/c/2aa9ea2bd5146d237c8cc16d8737d878b0298a94 Added Reference https://git.kernel.org/stable/c/315d2e5741a81b0be763e80413a2677e22b7e596 Added Reference https://git.kernel.org/stable/c/3f190956404da55560056ce20606010e18bc059c Added Reference https://git.kernel.org/stable/c/84c4c36acd5c4b2558b5069f869a165b2c655c84