AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-68107

HIGH · CVSS 8.8 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

A potential time-of-check to time-of-use (TOCTOU) vulnerability exists in the Linux kernel's AMD GPU driver, specifically related to the handling of the parameter length in the video coding engine. This flaw could allow an attacker to exploit changes in the instruction buffer (IB) contents between reads, potentially leading to unauthorized access or manipulation of data. Organizations using affected Linux distributions with AMD GPU hardware should prioritize applying the relevant updates to mitigate this risk.

CVE
CVE-2026-68107
Severity
HIGH
CVSS
8.8
EPSS
0.13%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn4: avoid rereading IB param length Reuse the parameter length returned by vcn_v4_0_enc_find_ib_param() instead of rereading it from the IB. This avoids a potential TOCTOU issue if the IB contents change between reads. (cherry picked from commit dbb02b4755f8c1f3773263f2d779872c1c0c073a)