Junglewise Threat Intelligence

CVE-2026-74353: Linux kernel amdkfd queue management recovery handling

CVE-2026-74353 · Severity: info · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's AMD KFD (Kernel Fusion Driver) component manages GPU queues for AMD graphics processors. A logic flaw in queue suspension and recovery could leave GPU queues in an inconsistent state, potentially causing GPU compute workloads to hang or fail unexpectedly.

Technical details

The vulnerability exists in the kfd_dqm_suspend_bad_queue_mes() function within drivers/gpu/drm/amd/amdkfd/kfd_device_queue_manager.c. The bug involves improper error handling during GPU queue suspension and resumption: if suspend_all_queues_mes() failed, the function would exit early via goto without calling resume_all_queues_mes(), leaving suspended queues in an inactive state. The fix ensures that resume_all_queues_mes() is always called after processing bad queues, allowing good queues to be properly restored regardless of intermediate failures. This is a local logic error affecting GPU compute queue management, typically exploitable only by local processes with GPU access.

Affected products

  • Linux Linux kernel Multiple versions (patched in stable series)

Timeline

  • 2026-08-15: disclosed
  • 2026-05-06: patched: Upstream commit 56ae73c92e200e630c2bdf1e98c88b86c8483b37

References

Related threats