PatchSiren cyber security CVE debrief
CVE-2026-23468 Unknown Vendor CVE debrief
CVE-2026-23468 is a Linux kernel amdgpu DRM issue where userspace could supply an arbitrarily large BO list entry count, leading to excessive memory use and long list processing. The fix adds a hard cap of 128k entries and returns -EINVAL when the limit is exceeded.
- Vendor
- Unknown Vendor
- Product
- Unknown
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-03
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-03
- Advisory updated
- 2026-07-24
Who should care
Linux kernel and distribution maintainers, GPU/graphics stack operators, and administrators of systems with AMDGPU enabled—especially where untrusted local users or sandboxed workloads can reach the affected userspace-to-kernel interface.
Technical summary
The issue is in drm/amdgpu BO list handling. The bo_number field could be set to an arbitrary number of entries. While prior overflow checks prevented an out-of-bounds allocation, they did not prevent very large allocations or expensive processing of the list. The resolved change imposes a hard upper bound of 128k BO list entries, which is described as sufficient for realistic workloads, and rejects larger requests with -EINVAL. The primary impact described in the source is availability/resource exhaustion, not code execution or memory corruption.
Defensive priority
Medium: the described impact is resource exhaustion and degraded performance in the Linux kernel amdgpu path. Prioritize on systems that expose the affected interface to untrusted local userspace or multi-tenant workloads.
Recommended defensive actions
- Apply the kernel fix that limits amdgpu BO list entries to 128k and ensure vendor/stable kernels include the backport.
- Review affected Linux kernel builds and AMDGPU-enabled fleets for the patched commit or downstream equivalent.
- Treat the issue as an availability hardening item: monitor for unusually large BO list requests or unexpected GPU-related memory pressure.
- If you maintain downstream kernels, verify that the returned error path (-EINVAL) is preserved for requests above the limit.
Evidence notes
The source description states that userspace can pass an arbitrary number of BO list entries via bo_number, that prior overflow checks did not stop excessive allocation/processing, and that the fix introduces a 128k limit with -EINVAL on overflow. The NVD modified record lists kernel.org stable commit references associated with the fix. No CVSS score or KEV entry was provided in the supplied data.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-23468 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-23468
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-23468 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-23468
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/2723e6851309531ce61aed74e93a0cd268cc862a
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/5ce4a38e6c2488949e373d5066303f9c128db614
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/6270b1a5dab94665d7adce3dc78bc9066ed28bdd
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/e620378aab78d415bd8a15a2f91c145906520288
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/f462624a6e4b5f1ec2664c2c53e408b2f4fb53e9
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.