AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-74417

UNKNOWN · CVSS N/A

Source: NVD + CISA KEV + EPSS · Published 2026-08-15 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's radeon graphics driver, specifically in the `radeon_align_pitch()` function, which is susceptible to integer overflow during pitch alignment calculations. This can lead to the creation of invalid or zero-sized buffers in `radeon_mode_dumb_create()`, potentially causing system instability or crashes. Organizations using Linux systems with radeon graphics should prioritize addressing this vulnerability to ensure the stability and security of their environments.

CVE
CVE-2026-74417
Severity
UNKNOWN
CVSS
N/A
EPSS
N/A
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: drm/radeon: fix integer overflow in radeon_align_pitch() radeon_align_pitch() has the same kind of overflow issue as the old amdgpu helper: both the alignment round-up add and the final 'aligned * cpp' calculation can overflow signed int. If that wraps, radeon_mode_dumb_create() can end up returning an invalid pitch or creating a zero-sized dumb buffer. Fix this by using check_add_overflow() for the alignment round-up and check_mul_overflow() for the final pitch calculation, returning 0 on overflow. Also reject zero pitch and size in radeon_mode_dumb_create(). Found via AST-based call-graph analysis using sqry.