CVE-2026-74446
Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
15/08/2026
Última modificación:
19/08/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
drm/amdkfd: hold event_mutex while checkpointing CRIU events<br />
<br />
kfd_criu_checkpoint_events() counts the entries in p->event_idr via<br />
kfd_get_num_events(), allocates an array sized to that count, and then<br />
walks the same IDR to fill it. Neither the count nor the walk holds<br />
p->event_mutex.<br />
<br />
The CRIU checkpoint caller holds only p->mutex. Event create and destroy<br />
(kfd_event_create()/kfd_event_destroy()) take p->event_mutex and do not<br />
take p->mutex, so a second thread in the same process can insert or remove<br />
events between the count and the walk. If an event is inserted, the walk<br />
iterates more entries than were counted and writes past the end of the<br />
ev_privs allocation; if an event is removed, the walk dereferences an<br />
entry that is being freed.<br />
<br />
Hold p->event_mutex across the count and the walk so both observe a<br />
consistent view of p->event_idr. The lock is released before<br />
copy_to_user(), which only touches the local buffer. The caller already<br />
holds p->mutex and the create/destroy paths never take p->mutex, so the<br />
p->mutex -> p->event_mutex order is not inverted and no deadlock is<br />
introduced.<br />
<br />
(cherry picked from commit ff57e223ab105795b05d3ef3f3c35a5a441bcbaa)
Impacto
Puntuación base 3.x
7.80
Gravedad 3.x
ALTA
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/2040b7e39027cb83bb8c7b84a4c95c2f6053c32f
- https://git.kernel.org/stable/c/6a52f48157fa7fb81e0c146937fd6c8b0c1cfdbd
- https://git.kernel.org/stable/c/8f7196f25b14f4290738639a50459b56a5ff2784
- https://git.kernel.org/stable/c/9a7f765985f64fd4a7a58f7bc9cd80a1f4230628
- https://git.kernel.org/stable/c/bed80be08c0bee47fa242a4256ac873477c815f8
- https://git.kernel.org/stable/c/ff8bc5a68a9a70bdc38d61a72c7a49c56063f9d2


