Junglewise Threat Intelligence

CVE-2026-74357: Linux kernel amdgpu slab-out-of-bounds in coredump ring dump

CVE-2026-74357 · Severity: high · CVSS 7.8 · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's AMD GPU driver contains a buffer overflow vulnerability in its error reporting mechanism. During GPU resets, the coredump function can write beyond allocated memory boundaries, potentially causing a kernel crash or providing an avenue for privilege escalation on systems using AMD GPUs.

Technical details

The vulnerability is a slab-out-of-bounds write (CWE-788) in amdgpu_coredump() within the ring content dump logic. The bug occurs because two separate loops iterate over adev->rings[] to count and then copy ring data; the first loop determines allocation size based on unsignalled fences, but the second loop may encounter additional signalled fences (updated concurrently by the fence driver), causing idx to exceed ring_count and overflow the kcalloc-ed buffer. The vulnerability is triggered during GPU resets, particularly under stress when fence signalling races with the coredump path. The attack vector is local (requires ability to trigger GPU resets), and the fix adds an idx < ring_count guard to prevent writes past the allocation.

Affected products

  • Linux Linux kernel multiple versions (exact range not specified in advisory)

Timeline

  • 2026-08-15: disclosed

Related threats