Executive brief
A vulnerability in the Linux kernel's AMD GPU driver could allow a local user to crash the system. The issue occurs when the system handles specific graphics queue requests incorrectly, leading to a kernel panic. This results in a complete loss of system availability until it is rebooted.
Technical details
A NULL pointer dereference exists in the get_queue_ids() function within drivers/gpu/drm/amd/amdkfd/kfd_device_queue_manager.c. When usr_queue_id_array is NULL but num_queues is non-zero, the function returns NULL. Callers such as suspend_queues() only validate the return value using IS_ERR(), which fails to catch a NULL return. This leads to a NULL pointer dereference in q_array_invalidate(). A local attacker can trigger this via the kfd_ioctl_set_debug_trap() IOCTL by providing a non-zero num_queues with a zero queue_array_ptr. The issue has been patched by ensuring get_queue_ids() returns ERR_PTR(-EINVAL) in this scenario.
Affected products
- Linux Linux Kernel 6.5 to 6.6.143, 6.12.94, 6.18.36, 7.0.13
Timeline
- 2026-06-25: advisory: CVE-2026-53144 published
- 2026-06-03: patched: Initial fix committed to mainline kernel
References
- https://git.kernel.org/stable/c/2bd550b547deabef98bd3b017ff743b7c34d3a6d
- https://git.kernel.org/stable/c/62bd09e23a23da70f9aae02748eba3e6bd93095d
- https://git.kernel.org/stable/c/72e259a32084c42816152c346096d2edd4213e23
- https://git.kernel.org/stable/c/daeceb0fe2a19651c58bbfa3d9d515ecb6ca8996
- https://git.kernel.org/stable/c/e1965e8913cfbf17622ca12638e7a07f68ba0848