CVE-2026-89818
Description
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn: fix integer overflow in dec_msg buffer count check If the supplied msg[2] (num_buffers) is 0x3FFFFFFF, the expression 6 + num_buffers * 4 wraps to 2 and the bounds check passes, letting the parser loop far past the end of the message BO. Triggering it additionally requires a ~4GiB mapping so that msg[1] survives the earlier "header does not fit in BO" check. Rewrite the test in division form, which is overflow-free by construction. Also update the message to reflect that msg is invalid.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or — if you've already worked around this in production — publish your fix to the community-verified tier.
Propose a mitigation on Community Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
References
- https://git.kernel.org/stable/c/47799e1f893d47d8af231710a61065e3ec8a13e8
- https://git.kernel.org/stable/c/4d7390530853eb7befda9cc786e4c86e8ad7ac9e
- https://git.kernel.org/stable/c/6dceaeceaa7c8396339f3ea34b0110cb912ca61b
- https://git.kernel.org/stable/c/7e28853c78c20bb8ba4c1dba702430cd05e09f76
- https://git.kernel.org/stable/c/9ae19bd60891bea0a7b7504cc8dbfe74570ac3b3
- https://git.kernel.org/stable/c/c2340281be4ddacb8c203e2bce59b126d1d6c4c8
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.