-

CVE-2026-98177

drm/amdkfd: Avoid integer underflow in EOP ring size calculation.

In the Linux kernel, the following vulnerability has been resolved:

drm/amdkfd: Avoid integer underflow in EOP ring size calculation.

The low 6 bits of cp_hqd_eop_control store the base-2 logarithm
of the EOP ring size. This was calculated as

order_base_2(q->eop_ring_buffer_size / 4) - 1

But order_base_2 can in theory return 0, so this could underflow
(although in practice the ring buffer size cannot be less than 4096).

Change this to

order_base_2(q->eop_ring_buffer_size / 8)

using properties of logarithms.

Also add to the above comment to make the mathematics more clear.

(cherry picked from commit f0f43fcf8b2b3a924cad9444340921c96ed5f634)
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version d696d536f0a97ac779d6176107ac4e96d0a2f8b9
Version < 287a34c4d712e0bdb67751e21316d9c8d75a528a
Status affected
Version d696d536f0a97ac779d6176107ac4e96d0a2f8b9
Version < 8ee521b8b189799e361d4233c5180ba56656d4d4
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 4.3
Status affected
Version 0
Version < 4.3
Status unaffected
Version <= 7.2.*
Version 7.2.8
Status unaffected
Version <= *
Version 7.3-rc4
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.041
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/287a34c4d712e0bdb67751e21316d9c8d75a528a
https://git.kernel.org/stable/c/8ee521b8b189799e361d4233c5180ba56656d4d4