CVE-2026-74417

Summary

In the Linux kernel, the following vulnerability has been resolved:

drm/radeon: fix integer overflow in radeon_align_pitch()

radeon_align_pitch() has the same kind of overflow issue as the old amdgpu helper: both the alignment round-up add and the final 'aligned * cpp' calculation can overflow signed int.

If that wraps, radeon_mode_dumb_create() can end up returning an invalid pitch or creating a zero-sized dumb buffer.

Fix this by using check_add_overflow() for the alignment round-up and check_mul_overflow() for the final pitch calculation, returning 0 on overflow. Also reject zero pitch and size in radeon_mode_dumb_create().

Found via AST-based call-graph analysis using sqry.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxff72145badb834e8051719ea66e024784d000cb4 < b7b44937c548c2c987fcdd129f8896741004bed6affected
LinuxLinuxff72145badb834e8051719ea66e024784d000cb4 < 415bb9893e249e46aa5159f7363a11512cf06fa9affected
LinuxLinuxff72145badb834e8051719ea66e024784d000cb4 < d9dfa176899d488e48bb7342d2c43ddd36e66318affected
LinuxLinuxff72145badb834e8051719ea66e024784d000cb4 < dfc7b5b5599472277e71e5bd2712740651c7c5beaffected
LinuxLinuxff72145badb834e8051719ea66e024784d000cb4 < ce3b24eb3ee8f82de851535f516bf21f83e82259affected
LinuxLinux2.6.39affected
LinuxLinux0 < 2.6.39unaffected
LinuxLinux6.6.145 <= 6.6.*unaffected
LinuxLinux6.12.97 <= 6.12.*unaffected
LinuxLinux6.18.40 <= 6.18.*unaffected
LinuxLinux7.1.5 <= 7.1.*unaffected
LinuxLinux7.2-rc1 <= *unaffected

Weaknesses

References