In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 The v11 MQD manager incorrectly assigned the CP-compute…
High CVSS 7.8
Summary
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 The v11 MQD manager incorrectly assigned the CP-compute variants of checkpoint_mqd/restore_mqd for KFD_MQD_TYPE_SDMA queues. These functions use sizeof(struct v11_compute_mqd) (2048 bytes) instead of sizeof(struct v11_sdma_mqd) (512 bytes), causing a 1536-byte overflow. During CRIU checkpoint of an SDMA queue on Navi3x: - checkpoint_mqd() reads 2048 by…
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://git.kernel.org/stable/c/16dad1fb0d783a4008de30e32d0038c393de05b1 Patch
- https://git.kernel.org/stable/c/2c5b66c9b4057b385566940935ebc32f6e6ebfd2 Patch
- https://git.kernel.org/stable/c/352ea59028ea48a6fff77f19ae28f98f71946a80 Patch
- https://git.kernel.org/stable/c/d02f05d30f35b036f7cbaf72de634affb5b38ec6 Patch
- https://git.kernel.org/stable/c/d3efcadfe3eea5b4263b8f2d4463b15c9fc46a64 Patch
- https://access.redhat.com/security/cve/CVE-2026-53143 Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2492719 Third Party Advisory
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53143.json Third Party Advisory
Timeline
- nvd_ingest NVD