CVE-2026-80907

medium

Description

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix UVD dpb min size calculation for H264 This should use actual number of references from the decode message, instead of maximum derived from level. (cherry picked from commit 64b525edb7e7bdfcdc77883c5e413804e2396856)

References

https://git.kernel.org/stable/c/ff4361816b6ba4bd29b548b17d993056a1ae2502

https://git.kernel.org/stable/c/fa96c24485942e277483cc70d9551d9e0111d7c5

https://git.kernel.org/stable/c/38914cb2c6afb5fe00241ea3438e655822196378

https://git.kernel.org/stable/c/33f4ef585368fe93523dca1e5440e006f6e5146e

https://git.kernel.org/stable/c/21a8084cd76223a13493237e04d45f5226d7cee6

Details

Source: Mitre, NVD

Published: 2026-09-04

Updated: 2026-09-04

Risk Information

CVSS v2

Base Score: 5.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.00156