SB20260812280 - Improper input validation in Linux kernel amd amdkfd driver
Published: August 12, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper input validation (CVE-ID: CVE-2026-68259)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper input validation in allocate_event_notification_slot in the amdkfd event handling code when processing a user-supplied restore event id. A local user can provide an out-of-bounds event id to cause a denial of service.
The issue is related to the restore_id option used by CRIU.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/4622214f0542f64b02c250db0f9c677eeb032d9b
- https://git.kernel.org/stable/c/50319efb865f72db45f191c8709511746d58ee0a
- https://git.kernel.org/stable/c/85eedff5f0c4aba5a66bc37a1bd6bcecd0d77b53
- https://git.kernel.org/stable/c/abeeb1947d81610c65349db4d89c6151f270e136
- https://git.kernel.org/stable/c/bb52249fbbe948875155ccd45cd8d74bf4ae747b