« Volver al listado

CVE-2026-74447

Estado: RecibidaAlta (7.8)—

In the Linux kernel, the following vulnerability has been resolved:

drm/amdkfd: fix uint32_t overflow in EOP ring buffer size alignment

eop_ring_buffer_size in struct queue_properties is a u32. In kfd_queue_acquire_buffers() the expected EOP buffer size is computed as ALIGN(eop_ring_buffer_size, PAGE_SIZE); ALIGN uses typeof(x), so the addition is done in 32-bit. A user-supplied size of 0xFFFFF001 wraps to 0, causing kfd_queue_buffer_get() to skip its exact-size check (gated on size != 0) and accept any BO mapped at the address. On GFX8/GFX9 the MQD cp_hqd_eop_control is then programmed for an 8KB EOP ring backed by a 4KB BO, so CP EOP writes can land past the buffer and fault the GPU.

Leer descripción completaMostrar menos

Cast the operand to u64 so the alignment is computed in 64-bit; the size check in kfd_queue_buffer_get() then rejects the oversized request.

(cherry picked from commit ae443117b742c357bfef3a7bddabf76fcf86e9ef)

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Desbordamiento de buffer local (AV:L, PR:L) permite escritura de memoria no autorizada en GPU, causando DoS y posible ejecución de código privilegiado vía corrupción de MQD.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-74447",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "ee0dc6c66a913260311876a4b2b53fe0b9bc3f94",
              "lessThan": "273548eb997c6be85230c1236b18784b09f6203c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "acfc84cfa70aca5b970faf152979bc97b9f8b0c0",
              "lessThan": "6dc0b4b39ed4f11ef70f76ecea8537e35f45342b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "42ea9cf2f16b7131cb7302acb3dac510968f8bdc",
              "lessThan": "7c54bd225d83bc1bcb44430ed4b4d3a5c36b1961",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "42ea9cf2f16b7131cb7302acb3dac510968f8bdc",
              "lessThan": "83463a96ea3c7d8ae636a4d6a0ba63c9ce410724",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c6ce687077cc67e4f3cbd0c89cb356fbbce91f4c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6.12.75",
              "lessThan": "6.12.103",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.18.16",
              "lessThan": "6.18.44",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.19.6",
              "lessThan": "6.20",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "drivers/gpu/drm/amd/amdkfd/kfd_queue.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7.0"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "7.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.103",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.44",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/gpu/drm/amd/amdkfd/kfd_queue.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-15T13:17:49.287",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/273548eb997c6be85230c1236b18784b09f6203c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6dc0b4b39ed4f11ef70f76ecea8537e35f45342b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7c54bd225d83bc1bcb44430ed4b4d3a5c36b1961",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/83463a96ea3c7d8ae636a4d6a0ba63c9ce410724",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: fix uint32_t overflow in EOP ring buffer size alignment\n\neop_ring_buffer_size in struct queue_properties is a u32. In\nkfd_queue_acquire_buffers() the expected EOP buffer size is computed as\nALIGN(eop_ring_buffer_size, PAGE_SIZE); ALIGN uses typeof(x), so the\naddition is done in 32-bit. A user-supplied size of 0xFFFFF001 wraps to\n0, causing kfd_queue_buffer_get() to skip its exact-size check (gated on\nsize != 0) and accept any BO mapped at the address. On GFX8/GFX9 the MQD\ncp_hqd_eop_control is then programmed for an 8KB EOP ring backed by a 4KB\nBO, so CP EOP writes can land past the buffer and fault the GPU.\n\nCast the operand to u64 so the alignment is computed in 64-bit; the size\ncheck in kfd_queue_buffer_get() then rejects the oversized request.\n\n(cherry picked from commit ae443117b742c357bfef3a7bddabf76fcf86e9ef)"
    }
  ],
  "lastModified": "2026-08-17T06:19:40.513",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}