In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Check bounds on allocate_doorbell allocated_doorbell has an option to set the doorbell id to a specific value (used by CRIU). This value was not bounds checked. Check to confirm it's less than KFD_MAX_NUM_OF_QUEUES_PER_PROCESS.
https://git.kernel.org/stable/c/e0cecd04a4fc4c75e375b91cf53eab5ba2e4ab7f
https://git.kernel.org/stable/c/c2c89118c27cbd3adace62c5df19d15b0e96ade1
https://git.kernel.org/stable/c/1f087bb8cf9e8797633da35c85435e557ef74d06