← All Advisories

CVE-2026-97496

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97496

Key Details

CVECVE-2026-97496
CVSS Score / Version7.1 (High) / CVSS v3.1
Updated2026-10-03
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is none; availability impact is high.
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

drm/amdkfd: Fix OOB memory exposure in get_wave_state()

The get_wave_state() function for v9 trusts cp_hqd_cntl_stack_size and

cp_hqd_cntl_stack_offset values read directly from the MQD, which are

written by GPU microcode and fully attacker-controlled on the

CRIU-restore path (via AMDKFD_IOC_RESTORE_PROCESS with H3).

this leads to an unbounded copy_to_user() that can leak adjacent

GTT/kernel memory. If offset > size, integer underflow produces a ~4 GiB

read length, if size is set to 1 MiB against a 4 KiB allocation, we leak

1 MiB of adjacent kernel memory (other queues' MQDs, ring buffers, KASLR

pointers).

Fix by clamping both cp_hqd_cntl_stack_size to the actual allocated

buffer size (q->ctl_stack_size) and cp_hqd_cntl_stack_offset to the

clamped size before performing arithmetic and copy_to_user().

This ensures we never read beyond the allocated kernel BO regardless of

attacker-supplied MQD field values. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97496
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97496