๐Ÿ” CVE Alert

CVE-2026-97496

UNKNOWN 0.0

drm/amdkfd: Fix OOB memory exposure in get_wave_state()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix OOB memory exposure in get_wave_state() The get_wave_state() function for v9 trusts cp_hqd_cntl_stack_size and cp_hqd_cntl_stack_offset values read directly from the MQD, which are written by GPU microcode and fully attacker-controlled on the CRIU-restore path (via AMDKFD_IOC_RESTORE_PROCESS with H3). this leads to an unbounded copy_to_user() that can leak adjacent GTT/kernel memory. If offset > size, integer underflow produces a ~4 GiB read length, if size is set to 1 MiB against a 4 KiB allocation, we leak 1 MiB of adjacent kernel memory (other queues' MQDs, ring buffers, KASLR pointers). Fix by clamping both cp_hqd_cntl_stack_size to the actual allocated buffer size (q->ctl_stack_size) and cp_hqd_cntl_stack_offset to the clamped size before performing arithmetic and copy_to_user(). This ensures we never read beyond the allocated kernel BO regardless of attacker-supplied MQD field values.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 24, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < d9183d974ddd5f09d029beaf359275ac20d4d5fe 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < ec646686613d8ab05b282d1463a7baa49fd6b83b 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 7ef144458f48d5589e36f1b3d83e83db2e5c5ba5 0 < 6.12.111 0 < 6.18.53
Linux / Linux
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/d9183d974ddd5f09d029beaf359275ac20d4d5fe git.kernel.org: https://git.kernel.org/stable/c/ec646686613d8ab05b282d1463a7baa49fd6b83b git.kernel.org: https://git.kernel.org/stable/c/7ef144458f48d5589e36f1b3d83e83db2e5c5ba5