CVE-2026-80539
CVE CVE-2026-80539EUVD EUVD-2026-66454Published 2026-08-26T14:37:13.000ZLast changed 2026-08-27T12:40:05.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: disallow multiple FENCE chunks in one submit amdgpu_cs_pass1() dispatches on chunk_id once per chunk without rejecting repeated ids. p->uf_bo is a single-slot field, so a submission carrying two AMDGPU_CHUNK_ID_FENCE chunks runs amdgpu_cs_p1_user_fence() twice, and the second run overwrites p->uf_bo with a freshly referenced BO without dropping the reference taken by the first. amdgpu_cs_parser_fini() only unrefs the final p->uf_bo, so every FENCE chunk but the last leaks a BO reference. The leaked BO outlives handle close and process exit. Reject duplicate FENCE chunks the same way commit fec5f8e8c6bc ("drm/amdgpu: disallow multiple BO_HANDLES chunks in one submit") did for p->bo_list. (cherry picked from commit 665b1fc2a1845206408f9a2c6da67101789edb82)
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux d38ceaf99ed015f2a0b9af3499791bd3a3daae21 <71aa45f7bfe46fbc6f51e7832573ff49b6005fea; patch: 6.18.46; d38ceaf99ed015f2a0b9af3499791bd3a3daae21 <7e9954e7212042ec808b06181b365b14f00c6f0a; d38ceaf99ed015f2a0b9af3499791bd3a3daae21 <5f46322e0b84af29e10eb951ff45bd6ea40640de; d38ceaf99ed015f2a0b9af3499791bd3a3daae21 <e3ee74d6dbbe409eb99546a7b0a02b2782f9021d; patch: 6.6.153; d38ceaf99ed015f2a0b9af3499791bd3a3daae21 <931cd1d1baeae68e8eb2c23bc1f3d8934dca6241; d38ceaf99ed015f2a0b9af3499791bd3a3daae21 <070229262ede37d17c4ea596650deb6e5eb5d106; 4.2; patch: 6.12.105; patch: 0; patch: 6.1.185; patch: 7.1.10; patch: 7.2
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.