Description
In the Linux kernel, the following vulnerability has been resolved:

drm/amdkfd: Add upper bound check for num_of_nodes

drm/amdkfd: Add upper bound check for num_of_nodes
in kfd_ioctl_get_process_apertures_new.

(cherry picked from commit 98ff46a5ea090c14d2cdb4f5b993b05d74f3949f)
Published: 2026-07-19
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Linux kernel's DRM amdkfd module had no upper bound check for the num_of_nodes parameter in the ioctl handler kfd_ioctl_get_process_apertures_new. This omission allows a user with access to the KFD interface to perform an out-of-bounds read of kernel memory, potentially exposing kernel data or causing a kernel panic that results in denial of service. The weakness is classified as an out-of-bounds read, CWE‑125.

Affected Systems

All systems running a Linux kernel version before the commit that introduced the bound check are vulnerable. Since the change is in the mainline kernel, any distribution shipping an older kernel remains at risk until the update is applied. The affected kernel component is the DRM amdkfd module of the Linux kernel.

Risk and Exploitability

The likely attack vector is local, requiring interaction with the KFD ioctl interface. The EPSS score of less than 1 % indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 5.5 reflects moderate severity, suggesting that successful exploitation would lead to service disruption but is unlikely to result in privilege escalation or remote compromise. An attacker would need local access or privileged ability to invoke the KFD call, so the risk is primarily for compromised or stolen hosts.

Generated by OpenCVE AI on August 12, 2026 at 10:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the kernel to a version that contains the bound-check commit
  • Reboot the system so that the new kernel is loaded
  • If the update cannot be applied immediately, restrict or disable KFD ioctl access for untrusted users, or disable the KFD subsystem until the fix is in place

Generated by OpenCVE AI on August 12, 2026 at 10:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Ubuntu USN Ubuntu USN USN-8574-1 Linux kernel (GCP FIPS) vulnerabilities
Ubuntu USN Ubuntu USN USN-8593-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8574-2 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8595-1 Linux kernel (Oracle) vulnerabilities
Ubuntu USN Ubuntu USN USN-8596-1 Linux kernel (NVIDIA) vulnerabilities
Ubuntu USN Ubuntu USN USN-8595-2 Linux kernel (AWS) vulnerabilities
Ubuntu USN Ubuntu USN USN-8603-1 Linux kernel (Azure) vulnerabilities
Ubuntu USN Ubuntu USN USN-8606-1 Linux kernel (Azure) vulnerabilities
Ubuntu USN Ubuntu USN USN-8607-1 Linux kernel (Azure CVM) vulnerabilities
Ubuntu USN Ubuntu USN USN-8608-1 Linux kernel (Azure FIPS) vulnerabilities
Ubuntu USN Ubuntu USN USN-8609-1 Linux kernel (Azure CVM) vulnerabilities
Ubuntu USN Ubuntu USN USN-8574-3 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8595-3 Linux kernel (AWS) vulnerabilities
Ubuntu USN Ubuntu USN USN-8618-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8619-1 Linux kernel (HWE) vulnerabilities
Ubuntu USN Ubuntu USN USN-8663-1 Linux kernel (NVIDIA) vulnerabilities
Ubuntu USN Ubuntu USN USN-8664-1 Linux kernel (NVIDIA BaseOS) vulnerabilities
Ubuntu USN Ubuntu USN USN-8665-1 Linux kernel (Raspberry Pi) vulnerabilities
History

Tue, 21 Jul 2026 00:15:00 +0000


Sun, 19 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Add upper bound check for num_of_nodes drm/amdkfd: Add upper bound check for num_of_nodes in kfd_ioctl_get_process_apertures_new. (cherry picked from commit 98ff46a5ea090c14d2cdb4f5b993b05d74f3949f)
Title drm/amdkfd: Add upper bound check for num_of_nodes
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-07-20T06:41:19.041Z

Reserved: 2026-06-09T07:44:35.401Z

Link: CVE-2026-53376

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-07-19T11:16:38.740

Modified: 2026-07-29T16:55:09.793

Link: CVE-2026-53376

cve-icon Redhat

Severity :

Publid Date: 2026-07-19T00:00:00Z

Links: CVE-2026-53376 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T10:15:02Z

Weaknesses