{
  "threat_severity" : "Low",
  "public_date" : "2026-08-12T00:00:00Z",
  "bugzilla" : {
    "description" : "kernel: drm/amdgpu/gfx8: drop unecessary BUG_ON()",
    "id" : "2514455",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2514455"
  },
  "cvss3" : {
    "cvss3_base_score" : "5.5",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
    "status" : "draft"
  },
  "cwe" : "CWE-617",
  "details" : [ "In the Linux kernel, the following vulnerability has been resolved:\ndrm/amdgpu/gfx8: drop unecessary BUG_ON()\nThere's no need to crash the kernel for this case.\n(cherry picked from commit 4d7c25208ca612b754f3bf39e9f16e725b828891)", "A flaw was found in the Linux kernel's drm/amdgpu/gfx8 component. An unnecessary BUG_ON() call within this component could lead to a system crash. This vulnerability could allow a local attacker to cause a Denial of Service (DoS), rendering the system unresponsive." ],
  "statement" : "Red Hat has determined that this vulnerability does not pose a significant risk to systems where the affected kernel module is loaded. The BUG_ON() assertion requires local access and specific GPU hardware conditions to trigger. Red Hat may apply this fix in a future kernel update.",
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 10",
    "fix_state" : "Fix deferred",
    "package_name" : "kernel",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Fix deferred",
    "package_name" : "kernel",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "fix_state" : "Fix deferred",
    "package_name" : "kernel",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Fix deferred",
    "package_name" : "kernel",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "fix_state" : "Fix deferred",
    "package_name" : "kernel",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9"
  }, {
    "product_name" : "Red Hat Enterprise Linux for NVIDIA 26",
    "fix_state" : "Fix deferred",
    "package_name" : "kernel",
    "cpe" : "cpe:/a:redhat:enterprise_linux_nvidia:"
  }, {
    "product_name" : "Red Hat Hardened Images",
    "fix_state" : "Not affected",
    "package_name" : "erlang27",
    "cpe" : "cpe:/a:redhat:hummingbird:1"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "rhcos",
    "cpe" : "cpe:/a:redhat:openshift:4"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-68430\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-68430\nhttps://lore.kernel.org/linux-cve-announce/2026081254-CVE-2026-68430-3979@gregkh/T" ],
  "name" : "CVE-2026-68430",
  "mitigation" : {
    "value" : "There is no mitigation for this flaw. Systems without AMD GFX8 GPU hardware are not affected by this issue in practice, as the vulnerable code path is only reached when the amdgpu driver is loaded for GFX8 hardware.",
    "lang" : "en:us"
  },
  "csaw" : false
}