PT-2026-104983 · Azure Linux · Kernel

Publicado

2026-09-24

·

Atualizado

2026-09-24

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
drm/amdkfd: Fix OOB memory exposure in get wave state()
The get wave state() function for v9 trusts cp hqd cntl stack size and cp hqd cntl stack offset values read directly from the MQD, which are written by GPU microcode and fully attacker-controlled on the CRIU-restore path (via AMDKFD IOC RESTORE PROCESS with H3).
this leads to an unbounded copy to user() that can leak adjacent GTT/kernel memory. If offset > size, integer underflow produces a ~4 GiB read length, if size is set to 1 MiB against a 4 KiB allocation, we leak 1 MiB of adjacent kernel memory (other queues' MQDs, ring buffers, KASLR pointers).
Fix by clamping both cp hqd cntl stack size to the actual allocated buffer size (q->ctl stack size) and cp hqd cntl stack offset to the clamped size before performing arithmetic and copy to user().
This ensures we never read beyond the allocated kernel BO regardless of attacker-supplied MQD field values.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

AZL-103965

Produtos afetados

Kernel