AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-68106

HIGH · CVSS 7.8 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's AMD GPU driver, where a division by zero can occur if the width or height of video frames is less than 16 pixels, potentially leading to application crashes during H264 decoding. This flaw can compromise system stability and should be prioritized by organizations using affected Linux distributions with AMD graphics hardware, particularly those relying on video processing capabilities.

CVE
CVE-2026-68106
Severity
HIGH
CVSS
7.8
EPSS
0.13%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix division by zero with invalid uvd dimensions When width or height is less than 16, width_in_mb or height_in_mb becomes 0, leading to fs_in_mb being 0. This causes a division by zero when calculating num_dpb_buffer in H264 and H264 Perf decode paths. Add validation to reject frames with width < 16 or height < 16 before performing any calculations that depend on these values. V2: Format change - move up all vaiable definitions. V3: Use warn_once to avoid spam. (cherry picked from commit 3e41d26c70b0a459d041cc19482a226c4b7423cb)