Description
In the Linux kernel, the following vulnerability has been resolved:

drm/amdkfd: fix 32-bit overflow in CWSR total size calculation

total_cwsr_size was computed in 32-bit before being used as a BO/SVM
allocation size.
With large ctx_save_restore_area_size and debug_memory_size
multiplied by the XCC count, the product can wrap,
yielding an undersized CWSR save area that firmware later overruns.

Promote total_cwsr_size to u64 and use check_add_overflow()/
check_mul_overflow() in both kfd_queue_acquire_buffers() and
kfd_queue_release_buffers().

(cherry picked from commit 319f7e13423ae3f486b9aea82f9ad2d6af0ee608)
Published: 2026-08-10
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Linux kernel "drm/amdkfd" component suffered a 32‑bit overflow in the calculation of the total CWSR (command‑queue save‑restore area) size. Because the value was stored in a 32‑bit type and used as an allocation size, a product of large "ctx_save_restore_area_size" and "debug_memory_size" values could wrap, producing an undersized allocation. The resulting memory corruption could overrun firmware structures, potentially enabling a kubeernel attacker to gain elevated privileges, corrupt memory, or cause a crash. This is an integer‑overflow leading to buffer‑overflow weakness (CWE‑674, CWE‑119).

Affected Systems

Affected systems include the Linux kernel, specifically the "drm/amdkfd" driver. No specific kernel versions are listed in the advisory; the vulnerability is fixed in commits referenced in the description.

Risk and Exploitability

The CVSS score is not provided and no EPSS value is available, but the vulnerability affects kernel memory management and requires a user with access to the AMD KFD subsystem. Because it requires interaction with the GPU driver, exploitability is likely limited to local privileged users or compromised kernel processes; no public exploits have been reported. The absence of KEV inclusion suggests that the vulnerability has not yet been classified as a known exploited threat, but the impact of privilege escalation warrants immediate attention.

Generated by OpenCVE AI on August 10, 2026 at 14:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a release that incorporates the amdkfd 32‑bit overflow fix (see the referenced commit hashes).
  • If a kernel upgrade is not immediately possible, apply the specific patches from the provided git references to the kernel source tree and rebuild the affected modules.
  • Recompile and reinstall the AMD KFD kernel module against the updated kernel to ensure consistency.

Generated by OpenCVE AI on August 10, 2026 at 14:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-674

Mon, 10 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: fix 32-bit overflow in CWSR total size calculation total_cwsr_size was computed in 32-bit before being used as a BO/SVM allocation size. With large ctx_save_restore_area_size and debug_memory_size multiplied by the XCC count, the product can wrap, yielding an undersized CWSR save area that firmware later overruns. Promote total_cwsr_size to u64 and use check_add_overflow()/ check_mul_overflow() in both kfd_queue_acquire_buffers() and kfd_queue_release_buffers(). (cherry picked from commit 319f7e13423ae3f486b9aea82f9ad2d6af0ee608)
Title drm/amdkfd: fix 32-bit overflow in CWSR total size calculation
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-10T12:01:30.547Z

Reserved: 2026-07-30T09:28:09.378Z

Link: CVE-2026-68257

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T19:30:17Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-674

    Uncontrolled Recursion