{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-97429","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-24T14:53:16.868Z","datePublished":"2026-09-24T16:03:42.269Z","dateUpdated":"2026-10-03T10:58:16.575Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-03T10:58:16.575Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: fix UAF race in destroy_queue_cpsch\n\nwait_on_destroy_queue() drops locks to wait for queue resume, allowing\na concurrent destroy to free the queue. Use is_being_destroyed flag to\nserialize destruction."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The UAF is reached from kfd_ioctl_destroy_queue() via AMDKFD_IOC_DESTROY_QUEUE on /dev/kfd, which calls pqm_destroy_queue() then destroy_queue_cpsch() and wait_on_destroy_queue(); the trigger is that local ioctl, not a remote protocol message.\nAC:L - After kfd_ioctl_runtime_enable() and kfd_ioctl_set_debug_trap() (KFD_IOC_DBG_TRAP_ENABLE then KFD_IOC_DBG_TRAP_SUSPEND_QUEUES) set debug_trap_enabled and is_suspended, wait_on_destroy_queue() drops p->mutex; a sibling thread then issues a second AMDKFD_IOC_DESTROY_QUEUE (or KFD_IOC_DBG_TRAP_DISABLE then destroy) and frees the same struct queue while the first sleeps.\nPR:L - kfd_open() has no capable() check, and AMDKFD_IOC_CREATE_QUEUE, AMDKFD_IOC_DESTROY_QUEUE, AMDKFD_IOC_RUNTIME_ENABLE and AMDKFD_IOC_DBG_TRAP are registered with flags 0; kfd_ioctl_set_debug_trap() skips the ptrace check when target==p, so an unprivileged /dev/kfd (render-group) user can trap, suspend and destroy their own queues.\nUI:N - The attacker opens their own /dev/kfd fd, enables debug trap on their own pid via kfd_ioctl_set_debug_trap(), suspends the queue with KFD_IOC_DBG_TRAP_SUSPEND_QUEUES, and issues the concurrent AMDKFD_IOC_DESTROY_QUEUE ioctls; no other user must mount, open, or interact.\nS:U - The use-after-free of struct queue in wait_on_destroy_queue()/destroy_queue_cpsch() and the later uninit_queue() in pqm_destroy_queue() stays in the host kernel that runs amdkfd; it is not a KVM/Xen guest-to-host escape or an IOMMU/DMA isolation bypass.\nC:H - While wait_on_destroy_queue() still evaluates q->properties.is_suspended, the racing pqm_destroy_queue() path kfree()s the same struct queue via uninit_queue() and its MQD via mqd_mgr->free_mqd(); that slab UAF of kernel queue/MQD objects is an arbitrary-read primitive.\nI:H - The overlapping destroy_queue_cpsch() then pqm_destroy_queue() path list_del()s q->list and kfree()s both the queue and process_queue_node while the waiter still holds those pointers, so the slab can be sprayed into an arbitrary kernel write or control-flow hijack.\nA:H - Using the freed struct queue in wait_on_destroy_queue() or the rest of destroy_queue_cpsch() (list_del(&q->list), free_mqd, uninit_queue) oopses the kernel; a use-after-free is scored High for availability even when not fully exploited."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/gpu/drm/amd/amdkfd/kfd_device_queue_manager.c"],"versions":[{"version":"a70a93fa568b4f05aba548dadb673703eccf5480","lessThan":"090b51e2dabf88c02c0b6b25ea672a8bddfba7d5","status":"affected","versionType":"git"},{"version":"a70a93fa568b4f05aba548dadb673703eccf5480","lessThan":"41144829f4645c2bd4cb501d34d253858f750c0a","status":"affected","versionType":"git"},{"version":"a70a93fa568b4f05aba548dadb673703eccf5480","lessThan":"d98c8032c29944e1e572e1f49a0613d364fece0f","status":"affected","versionType":"git"},{"version":"a70a93fa568b4f05aba548dadb673703eccf5480","lessThan":"ac081deaf16a639ea7dff2f285fe421a33c1ade0","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/gpu/drm/amd/amdkfd/kfd_device_queue_manager.c"],"versions":[{"version":"6.5","status":"affected"},{"version":"0","lessThan":"6.5","status":"unaffected","versionType":"semver"},{"version":"6.6.158","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.111","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.53","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.5","versionEndExcluding":"6.6.158"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.5","versionEndExcluding":"6.12.111"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.5","versionEndExcluding":"6.18.53"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.5","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/090b51e2dabf88c02c0b6b25ea672a8bddfba7d5"},{"url":"https://git.kernel.org/stable/c/41144829f4645c2bd4cb501d34d253858f750c0a"},{"url":"https://git.kernel.org/stable/c/d98c8032c29944e1e572e1f49a0613d364fece0f"},{"url":"https://git.kernel.org/stable/c/ac081deaf16a639ea7dff2f285fe421a33c1ade0"}],"title":"drm/amdkfd: fix UAF race in destroy_queue_cpsch","x_generator":{"engine":"bippy-1.2.0"}}}}