CVE-2026-68272
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1
Add a minimum-length check for the AMDGPU_CHUNK_ID_CP_GFX_SHADOW chunk in
amdgpu_cs_pass1(), matching the gate already present for the IB, FENCE and
BO_HANDLES chunk types.
The CP_GFX_SHADOW case previously shared a bare break with the dependency
and syncobj chunk types, which do not dereference a fixed-size struct. When
userspace submits this chunk with length_dw == 0, vmemdup_array_user() is
called with size 0 and returns ZERO_SIZE_PTR, which passes the IS_ERR()
check. amdgpu_cs_p2_shadow() then dereferences chunk->kdata as a struct
drm_amdgpu_cs_chunk_cp_gfx_shadow (reading shadow->flags), faulting on the
ZERO_SIZE_PTR and causing a NULL-pointer dereference.
This is reachable by an unprivileged process in the render group. Reject
undersized chunks with -EINVAL during pass1 so the bad submission is
rejected before pass2 ever dereferences the data.
(cherry picked from commit 7f61b2eef7415eccdb40850aca0de94211948657)
CSIRTS triage
- What
- The drm/amdgpu driver fails to validate CP_GFX_SHADOW chunk size in the CS pass1, allowing invalid input.
- Who is affected
- Systems running affected Linux kernel versions with AMD GPU support.
- Urgency
- Medium priority; affects GPU command submission validation.
- Action
- Apply Linux kernel security patches when available.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-68272
Get an email if CVE-2026-68272 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
Advisory coverage (2)
- mediumCVE-2026-68272: drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1msrc · 2026-08-11
- unknownCVE-2026-68272: In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: validate CP_GF…nvd · 2026-08-10
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-68272)