CVE-2026-97495

medium

Description

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Check bounds on allocate_doorbell allocated_doorbell has an option to set the doorbell id to a specific value (used by CRIU). This value was not bounds checked. Check to confirm it's less than KFD_MAX_NUM_OF_QUEUES_PER_PROCESS.

References

https://git.kernel.org/stable/c/e0cecd04a4fc4c75e375b91cf53eab5ba2e4ab7f

https://git.kernel.org/stable/c/c2c89118c27cbd3adace62c5df19d15b0e96ade1

https://git.kernel.org/stable/c/1f087bb8cf9e8797633da35c85435e557ef74d06

Details

Source: Mitre, NVD

Published: 2026-09-24

Updated: 2026-09-24

Risk Information

CVSS v2

Base Score: 7.2

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 5.5

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.00166