PT-2026-98115 · Linux · Linux Kernel
CVE-2026-97496
·
Published
2026-09-24
·
Updated
2026-09-28
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An out-of-bounds memory exposure exists in the
get wave state() function for v9. The function trusts cp hqd cntl stack size and cp hqd cntl stack offset values read from the MQD, which can be controlled by an attacker via the CRIU-restore path using AMDKFD IOC RESTORE PROCESS with H3. This leads to an unbounded copy to user() operation that can leak adjacent GTT or kernel memory, such as ring buffers, KASLR pointers, and other queues' MQDs. If the offset is greater than the size, an integer underflow can occur, resulting in a read length of approximately 4 GiB.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel