CVE-2026-68108
HighIn the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vce: fix integer overflow in image size Fix a security vulnerability where malicious VCE command streams with oversized dimensions (e.g. 65536×65536) cause 32-bit integer overflow, wrapping the calculated buffer size to 0. This bypasses validation and allows GPU firmware to perform out-of-bound memory access. The fix uses 64-bit arithmetic to detect overflow and rejects invalid dimensions before they reach the hardware. V2: remove redundant check V3: modify max height value V4: remove size64 (cherry picked from commit cbe408dba581755ad1279a487ec786d8927d778d)
CVSS 3.1 score
8.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected versions
Linux kernel versions
4.2
and later are affected. Fixed in
6.1.183,
6.6.148,
6.12.101,
6.18.42,
7.1.6,
7.2
and their respective stable series.
References
6 totalFrequently asked questions
-
What is CVE-2026-68108?
CVE-2026-68108 is a High severity Linux kernel vulnerability with a CVSS score of 8.8 out of 10 . It affects Linux kernel versions from 4.2 onward and has been patched in 6.1.183, 6.6.148, 6.12.101 and others. CVE-2026-68108 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.
-
What is the CVSS score for CVE-2026-68108?
CVE-2026-68108 has a CVSS score of 8.8 out of 10, rated High severity (CVSS 3.1). The vector string is
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. -
Is there a patch available for CVE-2026-68108?
Yes. CVE-2026-68108 has been patched. Fixed versions include 6.1.183, 6.6.148, 6.12.101 and others. If you are running Linux kernel 4.2 or later up to the fix versions, apply the relevant patch for your kernel branch.
-
Is CVE-2026-68108 actively exploited?
No. CVE-2026-68108 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.