CVE-2026-23468

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Limit BO list entry count to prevent resource exhaustion Userspace can pass an arbitrary number of BO list entries via the bo_number field. Although the previous multiplication overflow check prevents out-of-bounds allocation, a large number of entries could still cause excessive memory allocation (up to potentially gigabytes) and unnecessarily long list processing times. Introduce a hard limit of 128k entries per BO list, which is more than sufficient for any realistic use case (e.g., a single list containing all buffers in a large scene). This prevents memory exhaustion attacks and ensures predictable performance. Return -EINVAL if the requested entry count exceeds the limit (cherry picked from commit 688b87d39e0aa8135105b40dc167d74b5ada5332)
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*

History

24 Jul 2026, 22:10

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: drm/amdgpu: Limitar el número de entradas de la lista BO para prevenir el agotamiento de recursos El espacio de usuario puede pasar un número arbitrario de entradas de la lista BO a través del campo bo_number. Aunque la comprobación previa de desbordamiento de multiplicación previene la asignación fuera de límites, un gran número de entradas aún podría causar una asignación excesiva de memoria (potencialmente hasta gigabytes) y tiempos de procesamiento de lista innecesariamente largos. Se introduce un límite estricto de 128k entradas por lista BO, lo cual es más que suficiente para cualquier caso de uso realista (por ejemplo, una única lista que contenga todos los búferes en una escena grande). Esto previene ataques de agotamiento de memoria y asegura un rendimiento predecible. Devolver -EINVAL si el número de entradas solicitado excede el límite (cherry picked from commit 688b87d39e0aa8135105b40dc167d74b5ada5332)

01 Jun 2026, 17:16

Type Values Removed Values Added
References
  • () https://git.kernel.org/stable/c/c833d6c7199c5b5fca9ec95593acd539ec9c171c -

26 May 2026, 14:34

Type Values Removed Values Added
CPE cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*
CWE CWE-770
First Time Linux
Linux linux Kernel
References () https://git.kernel.org/stable/c/2723e6851309531ce61aed74e93a0cd268cc862a - () https://git.kernel.org/stable/c/2723e6851309531ce61aed74e93a0cd268cc862a - Patch
References () https://git.kernel.org/stable/c/5ce4a38e6c2488949e373d5066303f9c128db614 - () https://git.kernel.org/stable/c/5ce4a38e6c2488949e373d5066303f9c128db614 - Patch
References () https://git.kernel.org/stable/c/6270b1a5dab94665d7adce3dc78bc9066ed28bdd - () https://git.kernel.org/stable/c/6270b1a5dab94665d7adce3dc78bc9066ed28bdd - Patch
References () https://git.kernel.org/stable/c/e620378aab78d415bd8a15a2f91c145906520288 - () https://git.kernel.org/stable/c/e620378aab78d415bd8a15a2f91c145906520288 - Patch
References () https://git.kernel.org/stable/c/f462624a6e4b5f1ec2664c2c53e408b2f4fb53e9 - () https://git.kernel.org/stable/c/f462624a6e4b5f1ec2664c2c53e408b2f4fb53e9 - Patch
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5

17 May 2026, 16:16

Type Values Removed Values Added
References
  • () https://git.kernel.org/stable/c/e620378aab78d415bd8a15a2f91c145906520288 -

07 May 2026, 06:16

Type Values Removed Values Added
References
  • () https://git.kernel.org/stable/c/2723e6851309531ce61aed74e93a0cd268cc862a -

03 Apr 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-03 16:16

Updated : 2026-07-24 22:10


NVD link : CVE-2026-23468

Mitre link : CVE-2026-23468

CVE.ORG link : CVE-2026-23468


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-770

Allocation of Resources Without Limits or Throttling