Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-53143

Gravedad CVSS v3.1:
ALTA
Tipo:
CWE-787 Escritura fuera de límites
Fecha de publicación:
25/06/2026
Última modificación:
15/07/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11<br /> <br /> The v11 MQD manager incorrectly assigned the CP-compute variants of<br /> checkpoint_mqd/restore_mqd for KFD_MQD_TYPE_SDMA queues. These functions<br /> use sizeof(struct v11_compute_mqd) (2048 bytes) instead of sizeof(struct<br /> v11_sdma_mqd) (512 bytes), causing a 1536-byte overflow.<br /> <br /> During CRIU checkpoint of an SDMA queue on Navi3x:<br /> - checkpoint_mqd() reads 2048 bytes from a 512-byte SDMA MQD buffer,<br /> leaking 1536 bytes of adjacent GTT memory to userspace<br /> <br /> During CRIU restore:<br /> - restore_mqd() writes 2048 bytes into a 512-byte SDMA MQD buffer,<br /> corrupting 1536 bytes of adjacent GTT memory (often the ring buffer<br /> or neighboring MQDs)<br /> <br /> This is a copy-paste regression unique to v11. All other ASIC backends<br /> (cik, vi, v9, v10, v12) correctly use the SDMA-specific variants.<br /> <br /> Add checkpoint_mqd_sdma() and restore_mqd_sdma() functions that properly<br /> handle the smaller v11_sdma_mqd structure, matching the pattern used in<br /> other MQD managers.<br /> <br /> (cherry picked from commit 6fa41db7ffdec97d62433adf03b7b9b759af8c2c)

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.19 (incluyendo) 6.6.143 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (incluyendo) 6.12.94 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (incluyendo) 6.18.36 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.19 (incluyendo) 7.0.13 (excluyendo)
cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:*