Database/Kernel, userspace & hypervisor
Linux kernel (drivers/gpu/drm/radeon): The radeon video-encode command-stream parser used an uninitialised stack value
Impact
The radeon video-encode command-stream parser used an uninitialised stack value as the size argument when validating a relocation, so a tenant that crafts an encode command stream whose first opcode is the encode command gets the bounds check performed against garbage. That turns the CS parser's relocation validation into a coin flip and opens the door to out-of-bounds buffer access driven entirely from the ioctl.
Who can reach it
A container holding /dev/dri/renderD* on a host with a radeon-class AMD GPU submits a hand-built VCE command stream through the CS ioctl. No privilege beyond the render node; conditional on the radeon driver being loaded and the GPU exposing VCE, so it does not apply to amdgpu-era or NVIDIA nodes.
What to do
Update to a kernel with the fix commits below. Interim: blacklist the radeon module on nodes that do not need it, or drop /dev/dri from untrusted containers on radeon hosts.
References
Related entries
- Linux kernel (drivers/gpu/drm/xe): The Xe userptr path takes folio locks while holding the MMU notifier lock, whichCVE-2025-37868 · Linux kernel (drivers/gpu/drm/xe)Medium
- Linux kernel (arch/x86/kvm): A guest using its APIC timer in periodic mode can leave KVM programming an already-expiredCVE-2025-71104 · Linux kernel (arch/x86/kvm)Medium
- Linux kernel (drivers/vfio/pci/xe): Resetting a passed-through Intel GPU virtual function that does not supportCVE-2026-31601 · Linux kernel (drivers/vfio/pci/xe)Medium
- Linux kernel (net/xfrm): The async-event reply buffer was sized without accounting for the interface-ID attribute, soCVE-2026-43107 · Linux kernel (net/xfrm)Medium
- Linux kernel (drivers/iommu/amd): AMD-Vi hands out the completion-wait sequence number outside the IOMMU lock, soCVE-2026-43220 · Linux kernel (drivers/iommu/amd)Medium
- Linux kernel (net/xfrm): Tearing down an IPTFS security association cancels its hrtimers while holding the very locksCVE-2026-53197 · Linux kernel (net/xfrm)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.