CVE-2026-80908

UnknownEPSS 0.17%

Last modified

CVE-2026-80908 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Reject UVD message with dimensions above 4096 Fixes potential overflow in DPB size calculations. (cherry picked from commit 05e1387d151f71569fbe122d2c89f9db0c21dc10). EPSS estimates a 0.17% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Reject UVD message with dimensions above 4096 Fixes potential overflow in DPB size calculations. (cherry picked from commit 05e1387d151f71569fbe122d2c89f9db0c21dc10)

Metrics

EPSS Probability
0.17%

6.0th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= d38ceaf99ed015f2a0b9af3499791bd3a3daae21, < 8bae80eaed00e7ae28412a3cdf590f4beca72294; >= d38ceaf99ed015f2a0b9af3499791bd3a3daae21, < 9adc5e25f31d7ee7dfc18814499b6e3a6d402904; >= d38ceaf99ed015f2a0b9af3499791bd3a3daae21, < 382bef781ff441ce8055bdada57b8c291dc0fd30; >= d38ceaf99ed015f2a0b9af3499791bd3a3daae21, < 8435d41afcf2bc31ecee213ef651c12bd1a16d38; >= d38ceaf99ed015f2a0b9af3499791bd3a3daae21, < f7af372d3b892b95dd3cd1c6acf29daa39ba076d; >= d38ceaf99ed015f2a0b9af3499791bd3a3daae21, < 339deb76ee4859ea973e435c9a9a4a4fefc29338; >= d38ceaf99ed015f2a0b9af3499791bd3a3daae21, < 17fbb996c05f2190e0fa20927ca0b9804d481b02; >= d38ceaf99ed015f2a0b9af3499791bd3a3daae21, < 8c9aebcdd9f46f7a14b98d6ab18574b7a48fbb08
LinuxLinux4.2

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-80908?
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Reject UVD message with dimensions above 4096 Fixes potential overflow in DPB size calculations. (cherry picked from commit 05e1387d151f71569fbe122d2c89f9db0c21dc10)
How severe is CVE-2026-80908?
Severity scoring for CVE-2026-80908 is pending analysis. The EPSS model estimates a 0.17% probability of exploitation in the next 30 days.
How do I fix CVE-2026-80908?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-80908?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST