cbcvebase.
CVE-2026-23468
published 2026-04-03

CVE-2026-23468: In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Limit BO list entry count to prevent resource exhaustion Userspace can pass an…

PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.12%
2.5th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Limit BO list entry count to prevent resource exhaustion Userspace can pass an arbitrary number of BO list entries via the bo_number field. Although the previous multiplication overflow check prevents out-of-bounds allocation, a large number of entries could still cause excessive memory allocation (up to potentially gigabytes) and unnecessarily long list processing times. Introduce a hard limit of 128k entries per BO list, which is more than sufficient for any realistic use case (e.g., a single list containing all buffers in a large scene). This prevents memory exhaustion attacks and ensures predictable performance. Return -EINVAL if the requested entry count exceeds the limit (cherry picked from commit 688b87d39e0aa8135105b40dc167d74b5ada5332)

Affected

34 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.19.10-1 (forky)linux 6.19.10-1 (forky)
linuxlinux
linuxlinux>= d38ceaf99ed015f2a0b9af3499791bd3a3daae21 < c833d6c7199c5b5fca9ec95593acd539ec9c171cc833d6c7199c5b5fca9ec95593acd539ec9c171c
linuxlinux>= d38ceaf99ed015f2a0b9af3499791bd3a3daae21 < e620378aab78d415bd8a15a2f91c145906520288e620378aab78d415bd8a15a2f91c145906520288
linuxlinux>= d38ceaf99ed015f2a0b9af3499791bd3a3daae21 < 2723e6851309531ce61aed74e93a0cd268cc862a2723e6851309531ce61aed74e93a0cd268cc862a
linuxlinux>= d38ceaf99ed015f2a0b9af3499791bd3a3daae21 < 5ce4a38e6c2488949e373d5066303f9c128db6145ce4a38e6c2488949e373d5066303f9c128db614
linuxlinux>= d38ceaf99ed015f2a0b9af3499791bd3a3daae21 < f462624a6e4b5f1ec2664c2c53e408b2f4fb53e9f462624a6e4b5f1ec2664c2c53e408b2f4fb53e9
linuxlinux>= d38ceaf99ed015f2a0b9af3499791bd3a3daae21 < 6270b1a5dab94665d7adce3dc78bc9066ed28bdd6270b1a5dab94665d7adce3dc78bc9066ed28bdd
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.19.10-16.19.10-1
linuxlinux_kernel>= 4.2 < 6.6.1406.6.140
linuxlinux_kernel>= 6.13 < 6.18.206.18.20
linuxlinux_kernel>= 6.19 < 6.19.106.19.10
linuxlinux_kernel>= 6.7 < 6.12.866.12.86
msrcazl3_kernel_6.6.130.1-3_on_azure_linux_3.0
ubuntulinux
ubuntulinux-fips
ubuntulinux-gcp
ubuntulinux-gcp-6.8
ubuntulinux-gcp-fips
ubuntulinux-gke
ubuntulinux-gkeop

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
vendor_msrc5.5MEDIUM
vendor_ubuntu2.0LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.