Missing Authorization in Linux kernel - CVE-2026-97422

 

Missing Authorization in Linux kernel - CVE-2026-97422

Published: September 25, 2026


Vulnerability identifier: #VU152040
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-97422
CWE-ID: CWE-862
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to disclose information about GPU workloads.

The vulnerability exists due to improper authorization in the AMDKFD KFD SMI event handling when emitting PROCESS_START, PROCESS_END, and VMFAULT events with a process ID of zero. A local user can monitor GPU workloads to disclose information about GPU workloads.

The disclosed event data includes another process's PID and command name.


Affected software

Linux kernel

How to mitigate CVE-2026-97422

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins