What is CVE-2026-68108?
This is a vulnerability in the Linux kernel's amdgpu/vce driver, where malicious VCE command streams with oversized dimensions (e.g., 65536x65536) cause a 32-bit integer overflow, wrapping the calculated buffer size to 0. Users of AMD graphics cards should apply the kernel update to mitigate the issue.
Azərbaycanca: Bu, Linux kernel-in amdgpu/vce sürücüsündə aşkarlanmış boşluqdur. Zərərli VCE əmr axını vasitəsilə həddən artıq böyük ölçülər (məsələn, 65536x65536) göndərildikdə 32-bit integer overflow baş verir, bu da ayrılan bufer ölçüsünün sıfıra enməsinə səbəb olur. AMD qrafik kartı istifadəçiləri kernel yeniləməsini tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-190; shared vendor: Linux
FAQ2
Which device users are affected by CVE-2026-68108?
Users of AMD graphics cards are affected.
What happens when oversized dimensions are sent through a malicious VCE command stream in this vulnerability?
A 32-bit integer overflow occurs, wrapping the allocated buffer size to 0.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.