{"id":"CVE-2026-68276","summary":"drm/amdgpu/gfx: fix cleaner shader IB buffer overflow","details":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/gfx: fix cleaner shader IB buffer overflow\n\nThe cleaner shader sysfs path allocates a 16-dword (64 byte) IB but\nincorrectly fills (align_mask + 1) dwords. On GFX rings align_mask is\n0xff, so the loop wrote 256 dwords into a 64-byte buffer, causing a\nkernel page fault.\n\nThe IB only needs to be a minimal NOP shell to schedule the job; the\ncleaner shader itself is emitted on the ring via emit_cleaner_shader().\nFill 16 dwords to match the allocation.\n\nv2: Use ib_size_dw variable (Lijo)\n\n(cherry picked from commit bf21af331ebf72d0935fd70c73192414a422c03a)","modified":"2026-08-12T04:18:47.353074383Z","published":"2026-08-10T12:01:51.789Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68276.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/201633f47b542a99bb7baafdfcda7781249fb3d9"},{"type":"WEB","url":"https://git.kernel.org/stable/c/3e864bf2a32a1cbdf1e0f9c5a5a4176e8575f4a3"},{"type":"WEB","url":"https://git.kernel.org/stable/c/9cd9a983769a4d0e9cc80a287316ee79685d38b3"},{"type":"WEB","url":"https://git.kernel.org/stable/c/e28420e36542ae8b66a5bdcec419525f521bddf8"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68276.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-68276"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"d361ad5d2fc0e4d59d5d538092c9b37889756642"},{"fixed":"201633f47b542a99bb7baafdfcda7781249fb3d9"},{"fixed":"e28420e36542ae8b66a5bdcec419525f521bddf8"},{"fixed":"9cd9a983769a4d0e9cc80a287316ee79685d38b3"},{"fixed":"3e864bf2a32a1cbdf1e0f9c5a5a4176e8575f4a3"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68276.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.12.0"},{"fixed":"6.12.103"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.42"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.1.6"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68276.json"}}],"schema_version":"1.9.0"}