In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Validate command buffer payload count The count field in the command header is used to determine the valid payload size. Verify that the valid payload does not exceed the remaining buffer space.
https://git.kernel.org/stable/c/901ec3470994006bc8dd02399e16b675566c3416
https://git.kernel.org/stable/c/3ed2ae6b3fe869f99b75afd02045ba5c0c0773e2
https://git.kernel.org/stable/c/3464e751755172ddbb849c1bd92f5f59e95c59a1