7.1

CVE-2026-97496

drm/amdkfd: Fix OOB memory exposure in get_wave_state()

In the Linux kernel, the following vulnerability has been resolved:

drm/amdkfd: Fix OOB memory exposure in get_wave_state()

The get_wave_state() function for v9 trusts cp_hqd_cntl_stack_size and
cp_hqd_cntl_stack_offset values read directly from the MQD, which are
written by GPU microcode and fully attacker-controlled on the
CRIU-restore path (via AMDKFD_IOC_RESTORE_PROCESS with H3).

this leads to an unbounded copy_to_user() that can leak adjacent
GTT/kernel memory. If offset > size, integer underflow produces a ~4 GiB
read length, if size is set to 1 MiB against a 4 KiB allocation, we leak
1 MiB of adjacent kernel memory (other queues' MQDs, ring buffers, KASLR
pointers).

Fix by clamping both cp_hqd_cntl_stack_size to the actual allocated
buffer size (q->ctl_stack_size) and cp_hqd_cntl_stack_offset to the
clamped size before performing arithmetic and copy_to_user().

This ensures we never read beyond the allocated kernel BO regardless of
attacker-supplied MQD field values.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 42c6c48214b726c30918e8dc80e2168607d13ae4
Version < e2bef0f168be46692a6b900916ff5da3771480ed
Status affected
Version 42c6c48214b726c30918e8dc80e2168607d13ae4
Version < d9183d974ddd5f09d029beaf359275ac20d4d5fe
Status affected
Version 42c6c48214b726c30918e8dc80e2168607d13ae4
Version < ec646686613d8ab05b282d1463a7baa49fd6b83b
Status affected
Version 42c6c48214b726c30918e8dc80e2168607d13ae4
Version < 7ef144458f48d5589e36f1b3d83e83db2e5c5ba5
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.18
Status affected
Version 0
Version < 5.18
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.018
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.1 1.8 5.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/d9183d974ddd5f09d029beaf359275ac20d4d5fe
https://git.kernel.org/stable/c/ec646686613d8ab05b282d1463a7baa49fd6b83b
https://git.kernel.org/stable/c/7ef144458f48d5589e36f1b3d83e83db2e5c5ba5
https://git.kernel.org/stable/c/e2bef0f168be46692a6b900916ff5da3771480ed