CVE-2026-46218: Linux Kernel

High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Add bounds checking to ib_{get,set}_value The uvd/vce/vcn code accesses the IB at predefined offsets without checking that the IB is large enough. Check the bounds here. The caller is responsible for making sure it can handle arbitrary return values. Also make the idx a uint32_t to prevent overflows causing the condition to fail.

Affected products

  • Linux Linux Kernel: from 4.2, before 6.1.175 (fixed in 6.1.175); from 6.2, before 6.6.140 (fixed in 6.6.140); from 6.7, before 6.12.90 (fixed in 6.12.90); from 6.13, before 6.18.32 (fixed in 6.18.32); from 6.19, before 7.0.9 (fixed in 7.0.9)

Published 2026-05-28. Last modified 2026-06-17.