Executive brief
A vulnerability was identified in the Linux kernel's AMD GPU driver (amdkfd) that could allow a local user to cause a system crash. The issue occurs when the system fails to properly check the size of data provided by a user during certain graphics-related operations. This could lead to an out-of-bounds memory access, potentially impacting system stability or availability.
Technical details
An out-of-bounds (OOB) buffer access vulnerability exists in the 'amdkfd' driver within the Linux kernel. The root cause is a failure to validate the 'nattr' (number of attributes) field against the actual buffer size in the SVM (Shared Virtual Memory) ioctl handler. A local attacker with access to the KFD device can provide a user-controlled attribute count that exceeds the allocated buffer size, leading to OOB access. This has been mitigated by implementing a validation function 'kfd_ioctl_svm_validate' that uses 'struct_size' to ensure the expected size does not exceed the provided buffer size ('usize'). Fixes have been backported to multiple stable kernel branches.
Affected products
- Linux Linux kernel All versions prior to fixed stable releases (6.x, 5.x)
Timeline
- 2026-04-21: other: Initial patch authored by AMD
- 2026-05-28: advisory: CVE published in NVD
References
- https://git.kernel.org/stable/c/045e0ff208f0838a246c10204105126611b267a1
- https://git.kernel.org/stable/c/6abd3a4417cb73a7d0db7e25bf11fae1074bdba3
- https://git.kernel.org/stable/c/91c6dc5a41695d02dfc6299f106ac38a6c493e52
- https://git.kernel.org/stable/c/ccd060b5c7cc75ae7e211c250b97c5b6272e7efc
- https://git.kernel.org/stable/c/db9530a9873a7c85d2266a922589ebcf427fa631