CVE-2026-98177: drm/amdkfd: Avoid integer underflow in EOP ring size calculation.
In the Linux kernel, the following vulnerability has been resolved:
drm/amdkfd: Avoid integer underflow in EOP ring size calculation.
The low 6 bits of cphqdeopcontrol store the base-2 logarithm of the EOP ring size. This was calculated as
orderbase2(q->eopringbuffersize / 4) - 1
But orderbase2 can in theory return 0, so this could underflow (although in practice the ring buffer size cannot be less than 4096).
Change this to
orderbase2(q->eopringbuffersize / 8)
using properties of logarithms.
Also add to the above comment to make the mathematics more clear.
(cherry picked from commit f0f43fcf8b2b3a924cad9444340921c96ed5f634)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch f0f43fcf8b2b3a924cad9444340921c96ed5f634