8

CVE-2026-80747

Medienbericht

drm/amdkfd: Add bounds check for CRAT subtype length

In the Linux kernel, the following vulnerability has been resolved:

drm/amdkfd: Add bounds check for CRAT subtype length

The CRAT parser validates that the subtype header fits within the image,
but does not verify that the advertised subtype length fits. A malformed
CRAT table with an oversized length field causes out-of-bounds reads when
kfd_parse_subtype() casts the header to specific subtype structures.

Add validation that sub_type_hdr + length does not exceed the image
boundary before parsing the subtype contents.

(cherry picked from commit 48e1d1e6e8798aef0312e68d8e586021b5b3cf4d)
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 5b5c4e40a37e858e2bff8cd91be8e972256392c4
Version < ca91e0cc8087568e4b791648a7c01e804f48cb73
Status affected
Version 5b5c4e40a37e858e2bff8cd91be8e972256392c4
Version < 6e7566ba4739dd573c331adde1c96690f7a567bd
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 3.19
Status affected
Version 0
Version < 3.19
Status unaffected
Version <= 7.1.*
Version 7.1.10
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.058
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 8 2.5 5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
08.09.2026 20:38
https://git.kernel.org/stable/c/ca91e0cc8087568e4b791648a7c01e804f48cb73
https://git.kernel.org/stable/c/6e7566ba4739dd573c331adde1c96690f7a567bd