CVE-2026-74446
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
15/08/2026
Last modified:
19/08/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
drm/amdkfd: hold event_mutex while checkpointing CRIU events<br />
<br />
kfd_criu_checkpoint_events() counts the entries in p->event_idr via<br />
kfd_get_num_events(), allocates an array sized to that count, and then<br />
walks the same IDR to fill it. Neither the count nor the walk holds<br />
p->event_mutex.<br />
<br />
The CRIU checkpoint caller holds only p->mutex. Event create and destroy<br />
(kfd_event_create()/kfd_event_destroy()) take p->event_mutex and do not<br />
take p->mutex, so a second thread in the same process can insert or remove<br />
events between the count and the walk. If an event is inserted, the walk<br />
iterates more entries than were counted and writes past the end of the<br />
ev_privs allocation; if an event is removed, the walk dereferences an<br />
entry that is being freed.<br />
<br />
Hold p->event_mutex across the count and the walk so both observe a<br />
consistent view of p->event_idr. The lock is released before<br />
copy_to_user(), which only touches the local buffer. The caller already<br />
holds p->mutex and the create/destroy paths never take p->mutex, so the<br />
p->mutex -> p->event_mutex order is not inverted and no deadlock is<br />
introduced.<br />
<br />
(cherry picked from commit ff57e223ab105795b05d3ef3f3c35a5a441bcbaa)
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/2040b7e39027cb83bb8c7b84a4c95c2f6053c32f
- https://git.kernel.org/stable/c/6a52f48157fa7fb81e0c146937fd6c8b0c1cfdbd
- https://git.kernel.org/stable/c/8f7196f25b14f4290738639a50459b56a5ff2784
- https://git.kernel.org/stable/c/9a7f765985f64fd4a7a58f7bc9cd80a1f4230628
- https://git.kernel.org/stable/c/bed80be08c0bee47fa242a4256ac873477c815f8
- https://git.kernel.org/stable/c/ff8bc5a68a9a70bdc38d61a72c7a49c56063f9d2


