{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-97497","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-24T16:01:01.150Z","datePublished":"2026-09-24T16:04:44.515Z","dateUpdated":"2026-10-03T10:59:00.579Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-03T10:59:00.579Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: Check bounds for allocate_sdma_queue restore_sdma_id\n\nallocate_sdma_queue has an option where the sdma queue id can be\nspecified (used by CRIU). We weren't bounds-checking that\nvalue.\n\nConfirm it's less than the maximum number of queues."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The unbounded index is kfd_criu_queue_priv_data.sdma_id, copy_from_user'd in kfd_criu_restore_queue() from AMDKFD_IOC_CRIU_OP KFD_CRIU_OP_RESTORE on /dev/kfd, then passed as restore_sdma_id into allocate_sdma_queue() by create_queue_cpsch()/create_queue_nocpsch(); no network protocol carries that field.\nAC:L - A single crafted KFD_CRIU_OP_RESTORE QUEUE object with type KFD_QUEUE_TYPE_SDMA or KFD_QUEUE_TYPE_SDMA_XGMI and an oversized sdma_id makes allocate_sdma_queue() run test_bit()/clear_bit() on that index; the attacker supplies the whole criu_restore() blob, so no race or victim-owned GPU state is required.\nPR:L - kfd_ioctl() admits AMDKFD_IOC_CRIU_OP only when capable(CAP_CHECKPOINT_RESTORE) or capable(CAP_SYS_ADMIN). CAP_CHECKPOINT_RESTORE is the delegated non-root capability already held by CRIU tooling and container checkpoint services, matching limited local privilege rather than init-namespace root.\nUI:N - The attacker opens their own /dev/kfd (kfd_open -> kfd_init_apertures creates PDDs) and issues KFD_CRIU_OP_RESTORE against that process; no other user must mount media, open a file, or interact.\nS:U - allocate_sdma_queue()'s OOB test_bit()/clear_bit() on the kzalloc'd device_queue_manager sdma_bitmap corrupts host kernel slab inside amdkfd. That stays in the same kernel authority; it is not a KVM/Xen guest-to-host escape or an IOMMU/DMA bypass.\nC:H - restore_sdma_id is a user uint32_t used as the bit index into a KFD_MAX_SDMA_QUEUES (128-bit) dqm->sdma_bitmap. test_bit() of an out-of-range index is an unbounded kernel-bit read (the ioctl returns -EBUSY iff the bit is clear), which is not a few-byte leak.\nI:H - When that out-of-range bit is set, allocate_sdma_queue() does clear_bit(*restore_sdma_id, dqm->sdma_bitmap), a one-bit write at an attacker-chosen offset past the 128-bit map into later dqm fields (fence_addr, hung_db_array) or adjacent kmalloc objects, an OOB write.\nA:H - test_bit()/clear_bit() of a restore_sdma_id whose bitmap word is unmapped oopses inside allocate_sdma_queue(); the same OOB clear can smash dqm pointers and flags and panic the host."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/gpu/drm/amd/amdkfd/kfd_device_queue_manager.c"],"versions":[{"version":"2485c12c980a36bb9e23ababb07d73c4ac6a45af","lessThan":"41460d2dd0246f0ab7e80b103d34c8649e022999","status":"affected","versionType":"git"},{"version":"2485c12c980a36bb9e23ababb07d73c4ac6a45af","lessThan":"25e1b29ecc8da3609ba0072ca54a3b1fdd1578f3","status":"affected","versionType":"git"},{"version":"2485c12c980a36bb9e23ababb07d73c4ac6a45af","lessThan":"42f2bd50236b61ad0aeb2c233c990ee0d615fdad","status":"affected","versionType":"git"},{"version":"2485c12c980a36bb9e23ababb07d73c4ac6a45af","lessThan":"dd2870ca036e1d51baa59f942007b36a595b5890","status":"affected","versionType":"git"},{"version":"2485c12c980a36bb9e23ababb07d73c4ac6a45af","lessThan":"bfe9a7545b2a7be1c543f1741e16f2d5ec4116ae","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/gpu/drm/amd/amdkfd/kfd_device_queue_manager.c"],"versions":[{"version":"5.18","status":"affected"},{"version":"0","lessThan":"5.18","status":"unaffected","versionType":"semver"},{"version":"6.1.189","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.158","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.111","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.53","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.18","versionEndExcluding":"6.1.189"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.18","versionEndExcluding":"6.6.158"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.18","versionEndExcluding":"6.12.111"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.18","versionEndExcluding":"6.18.53"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.18","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/41460d2dd0246f0ab7e80b103d34c8649e022999"},{"url":"https://git.kernel.org/stable/c/25e1b29ecc8da3609ba0072ca54a3b1fdd1578f3"},{"url":"https://git.kernel.org/stable/c/42f2bd50236b61ad0aeb2c233c990ee0d615fdad"},{"url":"https://git.kernel.org/stable/c/dd2870ca036e1d51baa59f942007b36a595b5890"},{"url":"https://git.kernel.org/stable/c/bfe9a7545b2a7be1c543f1741e16f2d5ec4116ae"}],"title":"drm/amdkfd: Check bounds for allocate_sdma_queue restore_sdma_id","x_generator":{"engine":"bippy-1.2.0"}}}}