Junglewise Threat Intelligence

CVE-2026-72449: Linux kernel AMD KFD use-after-free in kfd_criu_resume_svm

CVE-2026-72449 · Severity: high · CVSS 7.8 · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's AMD KFD (Kernel Fusion Driver) contains a memory management bug in the CRIU (Checkpoint/Restore In Userspace) resume function that allows an unprivileged user with access to /dev/kfd to trigger use-after-free and double-free memory corruption. An attacker can exploit this by issuing repeated AMDKFD_IOC_CRIU_OP ioctl calls to crash the kernel or potentially execute arbitrary code, disrupting system stability and potentially compromising the kernel.

Technical details

The vulnerability is a use-after-free and double-free bug in the kfd_criu_resume_svm() function within drivers/gpu/drm/amd/amdkfd/kfd_svm.c. The cleanup code walks the criu_svm_metadata_list and frees entries without removing them from the list using list_del(). On a second AMDKFD_IOC_CRIU_OP ioctl call from the same process, the list_empty() check reads a dangling pointer (use-after-free), the loop traverses freed memory entries, and each is freed again (double-free). The vulnerability is reachable by any unprivileged user with render-group access to /dev/kfd and requires no special capabilities. The fix adds a list_del() call before each kfree(), and the existing list_for_each_entry_safe() iterator safely caches the next pointer during list manipulation. Patch is available in Linux kernel stable tree.

Affected products

  • Linux Linux kernel 5.0 and later (AMD KFD driver affected versions)

Timeline

  • 2026-08-15: disclosed
  • 2026-07-24: patched: Upstream fix in commit 6322d278a298e2c1430b9d2697743d3a04b788b1, stable backports available

References

Related threats