Junglewise Threat Intelligence

CVE-2026-46197: Linux Kernel amdkfd out-of-bounds access in SVM ioctl

CVE-2026-46197 · Severity: info · CVSS 5.5 · Published 2026-05-28

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's AMD GPU driver (amdkfd) that could allow a local user to cause a system crash. The issue occurs when the system fails to properly check the size of data provided by a user during certain graphics-related operations. This could lead to an out-of-bounds memory access, potentially impacting system stability or availability.

Technical details

An out-of-bounds (OOB) buffer access vulnerability exists in the 'amdkfd' driver within the Linux kernel. The root cause is a failure to validate the 'nattr' (number of attributes) field against the actual buffer size in the SVM (Shared Virtual Memory) ioctl handler. A local attacker with access to the KFD device can provide a user-controlled attribute count that exceeds the allocated buffer size, leading to OOB access. This has been mitigated by implementing a validation function 'kfd_ioctl_svm_validate' that uses 'struct_size' to ensure the expected size does not exceed the provided buffer size ('usize'). Fixes have been backported to multiple stable kernel branches.

Affected products

  • Linux Linux kernel All versions prior to fixed stable releases (6.x, 5.x)

Timeline

  • 2026-04-21: other: Initial patch authored by AMD
  • 2026-05-28: advisory: CVE published in NVD

References

Related threats