CVE-2026-97497

high

Description

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Check bounds for allocate_sdma_queue restore_sdma_id allocate_sdma_queue has an option where the sdma queue id can be specified (used by CRIU). We weren't bounds-checking that value. Confirm it's less than the maximum number of queues.

References

https://git.kernel.org/stable/c/dd2870ca036e1d51baa59f942007b36a595b5890

https://git.kernel.org/stable/c/bfe9a7545b2a7be1c543f1741e16f2d5ec4116ae

https://git.kernel.org/stable/c/42f2bd50236b61ad0aeb2c233c990ee0d615fdad

Details

Source: Mitre, NVD

Published: 2026-09-24

Updated: 2026-09-25

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

Severity: Medium

CVSS v3

Base Score: 7.8

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.00127