PT-2026-104983 · Azure Linux · Kernel
Publicado
2026-09-24
·
Atualizado
2026-09-24
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
drm/amdkfd: Fix OOB memory exposure in get wave state()
The get wave state() function for v9 trusts cp hqd cntl stack size and
cp hqd cntl stack offset values read directly from the MQD, which are
written by GPU microcode and fully attacker-controlled on the
CRIU-restore path (via AMDKFD IOC RESTORE PROCESS with H3).
this leads to an unbounded copy to user() that can leak adjacent
GTT/kernel memory. If offset > size, integer underflow produces a ~4 GiB
read length, if size is set to 1 MiB against a 4 KiB allocation, we leak
1 MiB of adjacent kernel memory (other queues' MQDs, ring buffers, KASLR
pointers).
Fix by clamping both cp hqd cntl stack size to the actual allocated
buffer size (q->ctl stack size) and cp hqd cntl stack offset to the
clamped size before performing arithmetic and copy to user().
This ensures we never read beyond the allocated kernel BO regardless of
attacker-supplied MQD field values.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Kernel