Description
In the Linux kernel, the following vulnerability has been resolved:

drm/amdkfd: Add upper bound check for num_of_nodes

drm/amdkfd: Add upper bound check for num_of_nodes
in kfd_ioctl_get_process_apertures_new.

(cherry picked from commit 98ff46a5ea090c14d2cdb4f5b993b05d74f3949f)
Published: 2026-07-19
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The kfd_ioctl_get_process_apertures_new handler in the DRM amdkfd module of the Linux kernel lacks an upper bound check for the num_of_nodes parameter. This omission permits an attacker to read beyond the intended buffer, potentially exposing kernel memory contents or causing a kernel panic. The consequence is a loss of system availability and possible leakage of sensitive data at the kernel level. This weakness is a classic out-of-bounds read (CWE‑125).

Affected Systems

All Linux kernel releases prior to the commit that introduced the bound check are affected. Since the commit resides in the mainline kernel, any vendor shipping a kernel version that does not yet incorporate this change—i.e., kernels older than the patched flavor—remains vulnerable. The patch is relevant to the standard Linux kernel and its derivatives.

Risk and Exploitability

Based on the description, it is inferred that the attack vector requires local interaction with the KFD ioctl interface. The EPSS score is reported as less than 1 %, and the vulnerability is not listed in the CISA KEV catalog, indicating a low exploitation probability. The attack requires local user privileges or the ability to invoke the KFD ioctl interface, so an attacker would need to gain local access to the target machine. While the risk is moderate due to limited attack vector and low available exploits, a successful exploitation would still cause a denial of service or data exposure at the kernel level.

Generated by OpenCVE AI on July 30, 2026 at 22:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the kernel to a version that includes the commit adding the upper bound check
  • Reboot the system so that the repaired kernel is booted
  • If an immediate kernel update cannot be performed, deny untrusted users access to the KFD ioctl interfaces or disable the KFD subsystem until the fix is applied

Generated by OpenCVE AI on July 30, 2026 at 22:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Ubuntu USN Ubuntu USN USN-8574-1 Linux kernel (GCP FIPS) vulnerabilities
Ubuntu USN Ubuntu USN USN-8593-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8574-2 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8595-1 Linux kernel (Oracle) vulnerabilities
Ubuntu USN Ubuntu USN USN-8596-1 Linux kernel (NVIDIA) vulnerabilities
Ubuntu USN Ubuntu USN USN-8595-2 Linux kernel (AWS) vulnerabilities
Ubuntu USN Ubuntu USN USN-8603-1 Linux kernel (Azure) vulnerabilities
Ubuntu USN Ubuntu USN USN-8606-1 Linux kernel (Azure) vulnerabilities
Ubuntu USN Ubuntu USN USN-8607-1 Linux kernel (Azure CVM) vulnerabilities
Ubuntu USN Ubuntu USN USN-8608-1 Linux kernel (Azure FIPS) vulnerabilities
Ubuntu USN Ubuntu USN USN-8609-1 Linux kernel (Azure CVM) vulnerabilities
Ubuntu USN Ubuntu USN USN-8574-3 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8595-3 Linux kernel (AWS) vulnerabilities
Ubuntu USN Ubuntu USN USN-8618-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8619-1 Linux kernel (HWE) vulnerabilities
History

Tue, 21 Jul 2026 00:15:00 +0000


Sun, 19 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Add upper bound check for num_of_nodes drm/amdkfd: Add upper bound check for num_of_nodes in kfd_ioctl_get_process_apertures_new. (cherry picked from commit 98ff46a5ea090c14d2cdb4f5b993b05d74f3949f)
Title drm/amdkfd: Add upper bound check for num_of_nodes
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-07-20T06:41:19.041Z

Reserved: 2026-06-09T07:44:35.401Z

Link: CVE-2026-53376

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

Severity :

Publid Date: 2026-07-19T00:00:00Z

Links: CVE-2026-53376 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T22:45:04Z

Weaknesses