7.8
/ 10
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Description
In the Linux kernel, the following vulnerability has been resolved:
drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set()
The kfd_event_page_set() function writes KFD_SIGNAL_EVENT_LIMIT * 8
bytes via memset without checking the buffer size parameter. This allows
unprivileged userspace to trigger an out-of bounds kernel memory write
by passing a small buffer, leading to potential privilege
escalation.
drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set()
The kfd_event_page_set() function writes KFD_SIGNAL_EVENT_LIMIT * 8
bytes via memset without checking the buffer size parameter. This allows
unprivileged userspace to trigger an out-of bounds kernel memory write
by passing a small buffer, leading to potential privilege
escalation.
Basic Information
ID
CVE-2026-43206
Source
Linux
Published
May 6, 2026 at 11:28
Modified
May 8, 2026 at 12:41
Affected Product
Vendor
Linux
Product
Linux
Version
0fc8011f89feb8b2c3008583b777d097e1974660
Affected Versions
Linux Linux 0fc8011f89feb8b2c3008583b777d097e1974660
Linux Linux 0fc8011f89feb8b2c3008583b777d097e1974660
Linux Linux 0fc8011f89feb8b2c3008583b777d097e1974660
Linux Linux 0fc8011f89feb8b2c3008583b777d097e1974660
Linux Linux 0fc8011f89feb8b2c3008583b777d097e1974660
Linux Linux 0fc8011f89feb8b2c3008583b777d097e1974660
Linux Linux 0fc8011f89feb8b2c3008583b777d097e1974660
Linux Linux 0fc8011f89feb8b2c3008583b777d097e1974660
Linux Linux 4.17
Linux Linux 0fc8011f89feb8b2c3008583b777d097e1974660
Linux Linux 0fc8011f89feb8b2c3008583b777d097e1974660
Linux Linux 0fc8011f89feb8b2c3008583b777d097e1974660
Linux Linux 0fc8011f89feb8b2c3008583b777d097e1974660
Linux Linux 0fc8011f89feb8b2c3008583b777d097e1974660
Linux Linux 0fc8011f89feb8b2c3008583b777d097e1974660
Linux Linux 0fc8011f89feb8b2c3008583b777d097e1974660
Linux Linux 4.17
References
- git.kernel.org /stable/c/3e04bc310d80b46eaf481f1fefcbcb37a187412d
- git.kernel.org /stable/c/de8d7a25cd2eb5875b1d8d4fbc7fe4b4138b781f
- git.kernel.org /stable/c/b4034442cb090e4a980bdcc1540948606cbc951b
- git.kernel.org /stable/c/4857c37c7ba9aa38b9a4c694e8bd8d0091c87940
- git.kernel.org /stable/c/75fb57efdd7863fffbc39db23e9cad7aafda26ed
- git.kernel.org /stable/c/bfcd6b53e1f4feb182952f4ff9a137c36ceaf20b
- git.kernel.org /stable/c/4e72f419e4ed44cb3b60506752d8688c20a60a9b
- git.kernel.org /stable/c/8a70a26c9f34baea6c3199a9862ddaff4554a96d