« Volver al listado

CVE-2026-80870

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

drm/amdkfd: Validate CRIU-restored IDs before idr_alloc

The KFD CRIU restore flow restores previously saved object IDs from userspace.

For event restore:

For BO restore:

In both cases, the restored ID comes from userspace-provided CRIU data.

idr_alloc() expects the ID range values to fit within signed int limits. If a restored ID is larger than INT_MAX, it can trigger a WARN in the IDR layer.

A kernel WARN is undesirable because it prints a warning trace and may cause a panic or reboot on systems with panic_on_warn enabled.

Smatch reported these paths as allowing unchecked userspace values to reach idr_alloc().

Leer descripción completaMostrar menos

Add INT_MAX validation before using restored IDs in:

- kfd_criu_restore_event() - criu_restore_memory_of_gpu()

If the restored ID is invalid, return -EINVAL.

This prevents invalid restore data from reaching the IDR layer and avoids WARN-triggering paths, while keeping valid restore behavior unchanged.

Detalles técnicos trazas, registros y código del informe original
  kfd_criu_restore_event()
      -> create_signal_event() / create_other_event()
          -> allocate_event_notification_slot()
              -> idr_alloc(..., *restore_id, *restore_id + 1, ...)

  criu_restore_memory_of_gpu()
      -> idr_alloc(..., bo_priv->idr_handle, ...)

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-80870",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "40e8a766a761f7fdc8530347527b344fddf6f1a8",
              "lessThan": "f8687018f24037056692c1e93c7d96cc72889d5b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "40e8a766a761f7fdc8530347527b344fddf6f1a8",
              "lessThan": "89a75e3349c4fae28cbedc711bc924cbc6293da2",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "40e8a766a761f7fdc8530347527b344fddf6f1a8",
              "lessThan": "085ea93bda71fee600cc12a17026598eb10dd1f9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "40e8a766a761f7fdc8530347527b344fddf6f1a8",
              "lessThan": "543ed0f61d56501cc585162da600bbedd7c08c0f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "40e8a766a761f7fdc8530347527b344fddf6f1a8",
              "lessThan": "cb6311f25a096621ac7ffd91b50d1bb1cfb63a96",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "40e8a766a761f7fdc8530347527b344fddf6f1a8",
              "lessThan": "85043dd49c2f51a37b22618168e3ae59ab92f0d6",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/gpu/drm/amd/amdkfd/kfd_chardev.c",
            "drivers/gpu/drm/amd/amdkfd/kfd_events.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.18"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.18",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.1.178",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.145",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.97",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.40",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/gpu/drm/amd/amdkfd/kfd_chardev.c",
            "drivers/gpu/drm/amd/amdkfd/kfd_events.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-04T17:16:58.860",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/085ea93bda71fee600cc12a17026598eb10dd1f9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/543ed0f61d56501cc585162da600bbedd7c08c0f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/85043dd49c2f51a37b22618168e3ae59ab92f0d6",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/89a75e3349c4fae28cbedc711bc924cbc6293da2",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/cb6311f25a096621ac7ffd91b50d1bb1cfb63a96",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f8687018f24037056692c1e93c7d96cc72889d5b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: Validate CRIU-restored IDs before idr_alloc\n\nThe KFD CRIU restore flow restores previously saved object IDs from\nuserspace.\n\nFor event restore:\n\n  kfd_criu_restore_event()\n      -> create_signal_event() / create_other_event()\n          -> allocate_event_notification_slot()\n              -> idr_alloc(..., *restore_id, *restore_id + 1, ...)\n\nFor BO restore:\n\n  criu_restore_memory_of_gpu()\n      -> idr_alloc(..., bo_priv->idr_handle, ...)\n\nIn both cases, the restored ID comes from userspace-provided CRIU data.\n\nidr_alloc() expects the ID range values to fit within signed int\nlimits. If a restored ID is larger than INT_MAX, it can trigger a WARN\nin the IDR layer.\n\nA kernel WARN is undesirable because it prints a warning trace and may\ncause a panic or reboot on systems with panic_on_warn enabled.\n\nSmatch reported these paths as allowing unchecked userspace values to\nreach idr_alloc().\n\nAdd INT_MAX validation before using restored IDs in:\n\n- kfd_criu_restore_event()\n- criu_restore_memory_of_gpu()\n\nIf the restored ID is invalid, return -EINVAL.\n\nThis prevents invalid restore data from reaching the IDR layer and\navoids WARN-triggering paths, while keeping valid restore behavior\nunchanged."
    }
  ],
  "lastModified": "2026-09-04T17:16:58.860",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}