Answer in brief
CVE-2026-68107 records a Unknown severity vulnerability in drm/amdgpu/vcn4: avoid rereading IB param length. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <bbbe6a2a8d8dc87243438d3ffea2083b52d882d9 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <ff6aa542d91d76a185f69bd1997b94a560ff5f6b || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <bd868c077f67589ed2a714307ceaade5f246e302 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <c309626bf91fa0a0b583575654e6e14e81f818a3 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <3b4082fabc67c9780b06eb959e59dd92fa79c0f0 || >=0 <6.6.148 || >=0 <6.12.101 || >=0 <6.18.42 || >=0 <7.1.6 | bbbe6a2a8d8dc87243438d3ffea2083b52d882d9, ff6aa542d91d76a185f69bd1997b94a560ff5f6b, bd868c077f67589ed2a714307ceaade5f246e302, c309626bf91fa0a0b583575654e6e14e81f818a3, 3b4082fabc67c9780b06eb959e59dd92fa79c0f0, 6.6.148, 6.12.101, 6.18.42, 7.1.6 |
Published upstream
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 10, 2026
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn4: avoid rereading IB param length Reuse the parameter length returned by vcn_v4_0_enc_find_ib_param() instead of rereading it from the IB. This avoids a potential TOCTOU issue if the IB contents change between reads. (cherry picked from commit dbb02b4755f8c1f3773263f2d779872c1c0c073a)
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-68107 records a Unknown severity vulnerability in drm/amdgpu/vcn4: avoid rereading IB param length. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <bbbe6a2a8d8dc87243438d3ffea2083b52d882d9 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <ff6aa542d91d76a185f69bd1997b94a560ff5f6b || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <bd868c077f67589ed2a714307ceaade5f246e302 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <c309626bf91fa0a0b583575654e6e14e81f818a3 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <3b4082fabc67c9780b06eb959e59dd92fa79c0f0 || >=0 <6.6.148 || >=0 <6.12.101 || >=0 <6.18.42 || >=0 <7.1.6 | bbbe6a2a8d8dc87243438d3ffea2083b52d882d9, ff6aa542d91d76a185f69bd1997b94a560ff5f6b, bd868c077f67589ed2a714307ceaade5f246e302, c309626bf91fa0a0b583575654e6e14e81f818a3, 3b4082fabc67c9780b06eb959e59dd92fa79c0f0, 6.6.148, 6.12.101, 6.18.42, 7.1.6 |
Published upstream
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 10, 2026
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn4: avoid rereading IB param length Reuse the parameter length returned by vcn_v4_0_enc_find_ib_param() instead of rereading it from the IB. This avoids a potential TOCTOU issue if the IB contents change between reads. (cherry picked from commit dbb02b4755f8c1f3773263f2d779872c1c0c073a)
Quoted source text, attributed separately from HOL analysis.