Executive brief
The AMD KFD (Kernel Fusion Driver) module in the Linux kernel contains an undefined behavior issue when calculating SDMA queue bitmaps. Under certain conditions, this could lead to unexpected kernel behavior or system instability. This affects systems using AMD GPUs with KFD support.
Technical details
The vulnerability is a shift-out-of-bounds undefined behavior (UBSAN) in the drm/amdkfd driver's initialize_cpsch() function. When get_num_sdma_queues() or get_num_xgmi_sdma_queues() returns 0 or a value equal to the number of bits in the operand, a bitwise shift operation exceeds the valid range, triggering undefined behavior. The vulnerable code performs ~0ULL >> (64 - count) where count could be 0 or 64, causing shifts by the full operand width. The fix adds bounds checking to set the bitmap to ULLONG_MAX when the count is >= BITS_PER_TYPE, otherwise performs a safe shift. This is a local kernel code path that could potentially be triggered on systems with misconfigured or defective AMD GPU queue configurations.
Affected products
- Linux Linux Kernel Multiple versions (drm/amdkfd module)
Timeline
- 2025-10-01: disclosed: Advisory published
- 2021-05-11: patched: Fix committed to stable kernel trees