PT-2026-106505 · Linux · Linux

CVE-2026-98176

·

Published

2026-10-06

·

Updated

2026-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
drm/amdkfd: Avoid integer underflow with ffs in EOP ring size calc
The low 6 bits of cp hqd eop control store the base-2 logarithm of the EOP ring size. This was calculated as
ffs(q->eop ring buffer size / sizeof(unsigned int)) - 1 - 1
But ffs can in theory return 1 or 0, so this could underflow (although in practice the ring buffer size cannot be less than 4096).
Change this to
ffs(q->eop ring buffer size / sizeof(unsigned int) / 4)
using properties of logarithms.
(cherry picked from commit 4f18c56630383c14bfc6b2d65f88f2f895d2121a)
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98176

Affected Products

Linux