← All Advisories

CVE-2026-97422

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97422

Key Details

CVECVE-2026-97422
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

drm/amdkfd: fix SMI event cross-process information leak

kfd_smi_ev_enabled() skips the suser privilege check when pid=0.

PROCESS_START, PROCESS_END, and VMFAULT events are emitted with

pid=0 while carrying another process's PID and command name, so any

/dev/kfd user in the render group can monitor all GPU workloads.

Pass the target process PID into kfd_smi_event_add() for these events

so the existing per-client filter restricts delivery to the owning

process or CAP_SYS_ADMIN subscribers. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97422
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97422