๐Ÿ” CVE Alert

CVE-2026-68257

HIGH 7.8

drm/amdkfd: fix 32-bit overflow in CWSR total size calculation

CVSS Score
7.8
EPSS Score
0.1%
EPSS Percentile
4th

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: fix 32-bit overflow in CWSR total size calculation total_cwsr_size was computed in 32-bit before being used as a BO/SVM allocation size. With large ctx_save_restore_area_size and debug_memory_size multiplied by the XCC count, the product can wrap, yielding an undersized CWSR save area that firmware later overruns. Promote total_cwsr_size to u64 and use check_add_overflow()/ check_mul_overflow() in both kfd_queue_acquire_buffers() and kfd_queue_release_buffers(). (cherry picked from commit 319f7e13423ae3f486b9aea82f9ad2d6af0ee608)

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 10, 2026
Last Updated Aug 18, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new high vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
325aa07165394b8e866ffe9ec1d4c99d9195b2f2 < b88ffe6593607364a8c06a48c6f29e55437cdf8e d15deafab5d722afb9e2f83c5edcdef9d9d98bd1 < abce3276c57e36c955627307469b9f009057a467 d15deafab5d722afb9e2f83c5edcdef9d9d98bd1 < 865532d54eb57b660b1cb1b0e1755776ce21b849 d15deafab5d722afb9e2f83c5edcdef9d9d98bd1 < 2b0386d4293920e690c0e017708f999b93cc729b 63600103d2ac5c09fdeec5b931b396e4e0efd5d8 6.12.59 < 6.12.101 6.17.9 < 6.18
Linux / Linux
6.18

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/b88ffe6593607364a8c06a48c6f29e55437cdf8e git.kernel.org: https://git.kernel.org/stable/c/abce3276c57e36c955627307469b9f009057a467 git.kernel.org: https://git.kernel.org/stable/c/865532d54eb57b660b1cb1b0e1755776ce21b849 git.kernel.org: https://git.kernel.org/stable/c/2b0386d4293920e690c0e017708f999b93cc729b