PT-2026-43745 · Linux+3 · Linux Kernel+3

·

CVE-2026-45878

·

Published

2026-02-06

·

Updated

2026-08-20

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the drm/amdkfd component where the address watch clear code receives watch id as an unsigned value, but certain helper functions use a signed integer. When a very large watch id is passed from userspace, it can be converted to a negative value, leading to invalid shifts and potential memory access outside the watch points array. Specifically, the function kfd dbg trap clear dev address watch() fails to properly validate the watch id via kfd dbg owns dev watch id(), which can result in a buffer overflow if the value exceeds the maximum signed integer limit.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:57251
ALSA-2026:57252
BDU:2026-12192
CVE-2026-45878
OPENSUSE-SU-2026:21555-1
SUSE-SU-2026:22108-1
SUSE-SU-2026:22137-1
SUSE-SU-2026:22433-1
SUSE-SU-2026:22458-1
SUSE-SU-2026:23066-1
SUSE-SU-2026:23068-1
SUSE-SU-2026:23221-1
SUSE-SU-2026:23231-1
SUSE-SU-2026:23237-1
SUSE-SU-2026:2482-1
SUSE-SU-2026:2591-1
SUSE-SU-2026:2632-1
USN-8492-1
USN-8492-2
USN-8492-3
USN-8492-4
USN-8492-5
USN-8497-1
USN-8498-1
USN-8499-1
USN-8606-1
USN-8607-1
USN-8609-1
USN-8619-1

Affected Products

Linuxmint
Linux Kernel
Rocky Linux
Ubuntu