← All Advisories

Linux Kernel amdxdna Missing Command Buffer Validation Scores 7.1

Last refreshed2026-09-26

Status: UPDATED  |  Advisory ID: CVE-2026-23424

Key Details

CVECVE-2026-23424
CVSS Score / Version7.1 (High) / CVSS v3.1
Updated2026-09-24
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is none; availability impact is high.
Affected productsLinux Linux Kernel
Exploitation prediction (EPSS)0.12% probability of exploitation in the next 30 days (2% percentile) -- FIRST.org's EPSS model.

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux Kernel
SubsystemsGeneral OT
SectorsAll Sectors

What to Know

In the Linux kernel, the following vulnerability has been resolved:

accel/amdxdna: Validate command buffer payload count

The count field in the command header is used to determine the valid

payload size. Verify that the valid payload does not exceed the remaining

buffer space.

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-23424
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-23424