Back to overview

CVE-2026-53143

Description
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 The v11 MQD manager incorrectly assigned the CP-compute variants of checkpoint_mqd/restore_mqd for KFD_MQD_TYPE_SDMA queues. These functions use sizeof(struct v11_compute_mqd) (2048 bytes) instead of sizeof(struct v11_sdma_mqd) (512 bytes), causing a 1536-byte overflow. During CRIU checkpoint of an SDMA queue on Navi3x: - checkpoint_mqd() reads 2048 bytes from a 512-byte SDMA MQD buffer, leaking 1536 bytes of adjacent GTT memory to userspace During CRIU restore: - restore_mqd() writes 2048 bytes into a 512-byte SDMA MQD buffer, corrupting 1536 bytes of adjacent GTT memory (often the ring buffer or neighboring MQDs) This is a copy-paste regression unique to v11. All other ASIC backends (cik, vi, v9, v10, v12) correctly use the SDMA-specific variants. Add checkpoint_mqd_sdma() and restore_mqd_sdma() functions that properly handle the smaller v11_sdma_mqd structure, matching the pattern used in other MQD managers. (cherry picked from commit 6fa41db7ffdec97d62433adf03b7b9b759af8c2c)

Metadata

CVE ID
CVE-2026-53143
State
PUBLISHED
Assigner
Linux
Reserved
2026-06-09 07:44 UTC
Published
2026-06-25 08:38 UTC
Last updated
2026-06-25 08:38 UTC
Vendor / Product
Linux / Linux
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (2)
VendorProductPlatformVersions
Linux Linux cc009e613de6560eb499f8bc92c80a737752cb30 < 16dad1fb0d783a4008de30e32d0038c393de05b1, cc009e613de6560eb499f8bc92c80a737752cb30 < 2c5b66c9b4057b385566940935ebc32f6e6ebfd2, cc009e613de6560eb499f8bc92c80a737752cb30 < d3efcadfe3eea5b4263b8f2d4463b15c9fc46a64, cc009e613de6560eb499f8bc92c80a737752cb30 < d02f05d30f35b036f7cbaf72de634affb5b38ec6 …
Linux Linux 5.19, 0 < 5.19, 6.6.143 ≤ 6.6.*, 6.12.94 ≤ 6.12.* …
Back to overview