SB2026072167 - Improper input validation in Linux kernel amd amdkfd driver
Published: July 21, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper input validation (CVE-ID: CVE-2026-53376)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper input validation in kfd_ioctl_get_process_apertures_new when handling a num_of_nodes value supplied to the ioctl. A local user can supply a crafted num_of_nodes value to cause a denial of service.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/44d5a450c04d3d734c13a03561c3131020d66edf
- https://git.kernel.org/stable/c/4a8093c7def141cc6e854fbe3f9693867982418f
- https://git.kernel.org/stable/c/6ba6ec5fcbb0d03ca11ed1cc38d57a7deb6c6b20
- https://git.kernel.org/stable/c/74b73fa56a395d46745e4f245225963e9f8be7f1
- https://git.kernel.org/stable/c/7b80137eb8aa9d1cbfe7ccf3eeb1faa94ae35d7e