CVE Database
/

CVE-2026-23424

Back to search

CVE-2026-23424

Published: Apr 3, 2026

Modified: May 11, 2026

PUBLISHED

CVSS v3.1

7.1

HIGH

Description

In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Validate command buffer payload count The count field in the command header is used to determine the valid payload size. Verify that the valid payload does not exceed the remaining buffer space.

VendorProductVersions

Linux

Linux

affected
aac243092b707bb3018e951d470cc1a9bcbaba6c - < 3464e751755172ddbb849c1bd92f5f59e95c59a1
affected
aac243092b707bb3018e951d470cc1a9bcbaba6c - < 3ed2ae6b3fe869f99b75afd02045ba5c0c0773e2
affected
aac243092b707bb3018e951d470cc1a9bcbaba6c - < 901ec3470994006bc8dd02399e16b675566c3416

Linux

Linux

affected
6.14
unaffected
0 - < 6.14
unaffected
6.18.17 - <= 6.18.*
unaffected
6.19.7 - <= 6.19.*
unaffected
7.0 - <= *

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Attack Vector

Local

Attack Complexity

Low

Privileges Required

Low

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

None

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now