CVE-2026-53143

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
25/06/2026
Last modified:
15/07/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11<br /> <br /> The v11 MQD manager incorrectly assigned the CP-compute variants of<br /> checkpoint_mqd/restore_mqd for KFD_MQD_TYPE_SDMA queues. These functions<br /> use sizeof(struct v11_compute_mqd) (2048 bytes) instead of sizeof(struct<br /> v11_sdma_mqd) (512 bytes), causing a 1536-byte overflow.<br /> <br /> During CRIU checkpoint of an SDMA queue on Navi3x:<br /> - checkpoint_mqd() reads 2048 bytes from a 512-byte SDMA MQD buffer,<br /> leaking 1536 bytes of adjacent GTT memory to userspace<br /> <br /> During CRIU restore:<br /> - restore_mqd() writes 2048 bytes into a 512-byte SDMA MQD buffer,<br /> corrupting 1536 bytes of adjacent GTT memory (often the ring buffer<br /> or neighboring MQDs)<br /> <br /> This is a copy-paste regression unique to v11. All other ASIC backends<br /> (cik, vi, v9, v10, v12) correctly use the SDMA-specific variants.<br /> <br /> Add checkpoint_mqd_sdma() and restore_mqd_sdma() functions that properly<br /> handle the smaller v11_sdma_mqd structure, matching the pattern used in<br /> other MQD managers.<br /> <br /> (cherry picked from commit 6fa41db7ffdec97d62433adf03b7b9b759af8c2c)

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.19 (including) 6.6.143 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.12.94 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (including) 6.18.36 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.19 (including) 7.0.13 (excluding)
cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:*