Executive brief
A vulnerability in the Linux kernel's AMD GPU driver could allow a local user to gain elevated privileges on a system. The issue occurs when the system handles specific graphics event pages without properly verifying the size of the memory buffer provided by an application. An attacker could exploit this to overwrite sensitive kernel memory, potentially taking full control of the operating system.
Technical details
An out-of-bounds write vulnerability exists in the Linux kernel's 'amdkfd' driver within the kfd_event_page_set() function. The function uses memset to write a fixed amount of data (KFD_SIGNAL_EVENT_LIMIT * 8 bytes) to a buffer without first validating that the buffer size provided by userspace is sufficient. A local, unprivileged attacker can exploit this by passing a smaller-than-expected buffer, triggering a kernel memory corruption. This can be leveraged to achieve arbitrary code execution in kernel mode or local privilege escalation (LPE). The issue has been addressed by adding a size check to ensure the event page meets the minimum required length.
Affected products
- Linux Linux Kernel 4.17 to 5.10.252, 5.11 to 5.15.202, 5.16 to 6.1.165, 6.2 to 6.6.128, 6.7 to 6.12.75, 6.13 to 6.18.16, 6.19 to 6.19.6
Timeline
- 2026-02-02: other: Patch authored by Sunday Clement
- 2026-05-06: disclosed: CVE published by kernel.org
- 2026-05-06: advisory: NVD advisory published
References
- https://git.kernel.org/stable/c/3e04bc310d80b46eaf481f1fefcbcb37a187412d
- https://git.kernel.org/stable/c/4857c37c7ba9aa38b9a4c694e8bd8d0091c87940
- https://git.kernel.org/stable/c/4e72f419e4ed44cb3b60506752d8688c20a60a9b
- https://git.kernel.org/stable/c/75fb57efdd7863fffbc39db23e9cad7aafda26ed
- https://git.kernel.org/stable/c/8a70a26c9f34baea6c3199a9862ddaff4554a96d
- https://git.kernel.org/stable/c/b4034442cb090e4a980bdcc1540948606cbc951b
- https://git.kernel.org/stable/c/bfcd6b53e1f4feb182952f4ff9a137c36ceaf20b