Description
In the Linux kernel, the following vulnerability has been resolved:

drm/amdkfd: fix 32-bit overflow in CWSR total size calculation

total_cwsr_size was computed in 32-bit before being used as a BO/SVM
allocation size.
With large ctx_save_restore_area_size and debug_memory_size
multiplied by the XCC count, the product can wrap,
yielding an undersized CWSR save area that firmware later overruns.

Promote total_cwsr_size to u64 and use check_add_overflow()/
check_mul_overflow() in both kfd_queue_acquire_buffers() and
kfd_queue_release_buffers().

(cherry picked from commit 319f7e13423ae3f486b9aea82f9ad2d6af0ee608)
Published: 2026-08-10
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Linux kernel’s DRM AMD KFD driver contains an integer overflow in the calculation of the command‑queue save‑restore area (CWSR) total size. The total size was computed using a 32‑bit type and later used as an allocation size. If the product of ctx_save_restore_area_size and debug_memory_size multiplied by the XCC count overflows, the resulting buffer will be smaller than required, enabling firmware to overwrite memory beyond the allocated area. This can lead to a buffer overflow (CWE‑787), potentially corrupting kernel memory and creating a path for privilege escalation or system instability. The flaw exists in any Linux kernel that integrates the DRM AMD KFD driver before the patches in the advisory. No specific kernel release numbers are provided, so any system running a kernel prior to the referenced commits is considered vulnerable if it uses this subsystem.

Affected Systems

All Linux kernel installations employing the DRM AMD KFD driver prior to the fix in commit 319f7e13423ae3f486b9aea82f9ad2d6af0ee608 are affected. The vulnerability is present in the kernel, regardless of specific version numbers, as long as the subsystem has not been patched. The patch promotes the 32‑bit calculation to 64‑bit and adds overflow checks in kfd_queue_acquire_buffers() and kfd_queue_release_buffers().

Risk and Exploitability

The CVSS score of 7.8 indicates high severity, while the EPSS probability of less than 1% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, and no public exploits have been reported. Based on the description, it is inferred that exploitation requires local privileged access to the kernel, implying that an attacker must already have significant kernel or local user privileges to trigger the overflow.

Generated by OpenCVE AI on August 14, 2026 at 04:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply an updated kernel version that contains the AMDKFD 32‑bit overflow patch, or cherry‑pick the referenced commits into the running kernel source tree and rebuild the kernel.
  • Rebuild the AMD KFD kernel module against the updated kernel to ensure compatibility.
  • Reboot the system so the patched kernel and modules are loaded and in use.

Generated by OpenCVE AI on August 14, 2026 at 04:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4745-1 linux-6.12 security update
History

Fri, 14 Aug 2026 03:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-674

Thu, 13 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.0, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 12 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.0, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

threat_severity

Important


Mon, 10 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-674

Mon, 10 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: fix 32-bit overflow in CWSR total size calculation total_cwsr_size was computed in 32-bit before being used as a BO/SVM allocation size. With large ctx_save_restore_area_size and debug_memory_size multiplied by the XCC count, the product can wrap, yielding an undersized CWSR save area that firmware later overruns. Promote total_cwsr_size to u64 and use check_add_overflow()/ check_mul_overflow() in both kfd_queue_acquire_buffers() and kfd_queue_release_buffers(). (cherry picked from commit 319f7e13423ae3f486b9aea82f9ad2d6af0ee608)
Title drm/amdkfd: fix 32-bit overflow in CWSR total size calculation
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-18T06:55:54.208Z

Reserved: 2026-07-30T09:28:09.378Z

Link: CVE-2026-68257

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-10T13:20:14.367

Modified: 2026-08-18T07:16:51.380

Link: CVE-2026-68257

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-10T12:01:30Z

Links: CVE-2026-68257 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T04:30:17Z

Weaknesses