CVE-2026-80540

HIGHPre-NVD 7.87.8
EchelonGraph scoreHIGH confidence

Score 7.8 from GitHub Security Advisory (severity: HIGH) published 2026-08-27. a secondary CVSS source baseline 7.8; sources differ by 0.0.

Triggered by: GitHub Security Advisory CVSS
Sources: epss, ghsa, secondary
Trending — 5 sources updated this week
7.8EG
EchelonGraph verdictPlan a fixSerious severity, but no confirmed exploitation yet.
  • High severity, but no confirmed exploitation yet
CISA-KEV: Not listedEPSS PROB: 0%CVSS: 7.8Exploit: None knownExposed: 0

No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu: Fix UVD decode image min size calculation

This needs to use pitch instead of width. Also reject pitch over 4096 to avoid overflow.

(cherry picked from commit b41c8cb12e202b220353332ab87dc01a11f69304)

CVSS v3
7.8
EG Score
7.8(high)
EG Risk
40(Track)
EG Risk 40/100SSVC: Track

EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).

How it’s computed
Severity78% × 45%
Exploitation0% × 40%
Automatability30% × 15%
Action: Routine — remediate on your standard cadence.
EPSS PROB
0%
EPSS %ILE
3%
KEV
Not listed

Published

August 26, 2026

Last Modified

August 27, 2026

Advisory Details (8)

Auto-updated Aug 27, 2026
No patch confirmed yet.
generic

drm/amdgpu: Fix UVD decode image min size calculation - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/d058f7a6709441afe1784eecd8c0643dd84750bc
generic

drm/amdgpu: Fix UVD decode image min size calculation - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/bc7397a033ac52f6d8c9bb6510d61694b2a3fce7
generic

drm/amdgpu: Fix UVD decode image min size calculation - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/b8bb9ba3f101a1b0011f785a577a4a0a38371174
generic

drm/amdgpu: Fix UVD decode image min size calculation - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/b7549e3f96c78921751c4b3e69af729662130d83
generic

drm/amdgpu: Fix UVD decode image min size calculation - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/60539d517e8439621532d8c01091ac049c596b4b
generic

drm/amdgpu: Fix UVD decode image min size calculation - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/5cbd8af02b0b9c8723fa30edcf6fccab5170af8d
generic

drm/amdgpu: Fix UVD decode image min size calculation - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/271a7da84a6262a09de549912dcf6a749d169cb6
generic

drm/amdgpu: Fix UVD decode image min size calculation - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/25ee120f3803ad9e416ef9f76f4c3234cc4d645b

Vendor Advisories for CVE-2026-80540(1)

These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.

Data Freshness Timeline

(refreshed 15× in last 7d / 15× in last 30d)

Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.

  1. 2026-08-30 01:22 UTCEPSS rescore
  2. 2026-08-30 00:58 UTCGHSA enrichment
  3. 2026-08-29 12:30 UTCGHSA enrichment
  4. 2026-08-28 23:58 UTCEG score recompute
  5. 2026-08-28 23:58 UTCGHSA enrichment
  6. 2026-08-28 21:42 UTCEPSS rescore
  7. 2026-08-28 07:19 UTCGHSA enrichment
  8. 2026-08-27 18:50 UTCEG score recompute
  9. 2026-08-27 18:50 UTCGHSA enrichment
  10. 2026-08-27 14:25 UTCEPSS rescore
  11. 2026-08-27 06:20 UTCEG score recompute 7.80
  12. 2026-08-27 06:11 UTCMITRE cvelistV5CVSS v3 → 7.8 · severity → HIGH
  13. 2026-08-26 15:43 UTCNVD update
  14. 2026-08-26 14:43 UTCEG score recompute
  15. 2026-08-26 14:41 UTCMITRE cvelistV5first tracked

Frequently asked(5)

What is CVE-2026-80540?
CVE-2026-80540 is a high vulnerability published on August 26, 2026. In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix UVD decode image min size calculation This needs to use pitch instead of width. Also reject pitch over 4096 to avoid overflow. (cherry picked from commit b41c8cb12e202b220353332ab87dc01a11f69304)
When was CVE-2026-80540 disclosed?
CVE-2026-80540 was first published in the National Vulnerability Database on August 26, 2026, with the most recent update on August 27, 2026. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
Is CVE-2026-80540 actively exploited?
CVE-2026-80540 is not currently on CISA's Known Exploited Vulnerabilities catalog. FIRST EPSS estimates a 0% probability of exploitation in the next 30 days, which ranks it in the top 97.2% of all scored CVEs.
What is the CVSS score of CVE-2026-80540?
CVE-2026-80540 has a CVSS v3 base score of 7.8 (NVD).
How do I remediate CVE-2026-80540?
Patch to the fixed version published by the affected vendor. Where vendor advisories exist for CVE-2026-80540, EchelonGraph cross-links them in the Vendor Advisories panel below — those typically contain the canonical remediation steps, fixed version numbers, and any vendor-specific mitigations.

Dependency Blast Radius

Explore the affected products and dependency analysis for CVE-2026-80540

Explore →

Is Your Infrastructure Affected by CVE-2026-80540?

EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.