CVE-2026-74447: drm/amdkfd: fix uint32_t overflow in EOP ring buffer size alignment
In the Linux kernel, the following vulnerability has been resolved:
drm/amdkfd: fix uint32t overflow in EOP ring buffer size alignment
eopringbuffersize in struct queueproperties is a u32. In kfdqueueacquirebuffers() the expected EOP buffer size is computed as ALIGN(eopringbuffersize, PAGESIZE); ALIGN uses typeof(x), so the addition is done in 32-bit. A user-supplied size of 0xFFFFF001 wraps to 0, causing kfdqueuebufferget() to skip its exact-size check (gated on size != 0) and accept any BO mapped at the address. On GFX8/GFX9 the MQD cphqdeopcontrol is then programmed for an 8KB EOP ring backed by a 4KB BO, so CP EOP writes can land past the buffer and fault the GPU.
Cast the operand to u64 so the alignment is computed in 64-bit; the size check in kfdqueuebufferget() then rejects the oversized request.
(cherry picked from commit ae443117b742c357bfef3a7bddabf76fcf86e9ef)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-74447?
CVE-2026-74447 has a risk rating of 48.
How do I fix CVE-2026-74447?
To fix CVE-2026-74447, you need to update the Linux kernel to the latest patched version that includes the fix.
What systems are affected by CVE-2026-74447?
CVE-2026-74447 affects the Linux kernel in systems utilizing the amdkfd driver.
What does CVE-2026-74447 address in the Linux kernel?
CVE-2026-74447 addresses a uint32_t overflow issue in EOP ring buffer size alignment.
When was CVE-2026-74447 published?
CVE-2026-74447 was published on August 15, 2026.