Back

HIGH

drm/amdkfd: Check bounds on CRIU restore queue type and mqd size

Published Aug 10, 2026

Description

We weren't checking whether the values provided in the private data in kfd CRIU restore were within bounds.

For queue type, add a KFD_QUEUE_TYPE_MAX and ensure the provided type is less than it.

For mqd_size, add new function mqd_size_from_queue_type and confirm that the provided mqd_size matches expectations.

(cherry picked from commit f19d8086f6644083c913d70bfdeee20e1b6f46a5)

Affected products

Remediation

Red Hat statement

This issue affects AMDGPU KFD CRIU restore. Queue type and MQD size from restore blobs are not bounds-checked. Requires KFD compute and CRIU restore capability.

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Aug 10, 2026
Updated Aug 18, 2026
Reserved Jul 30, 2026
NVD
Status Received
Modified Aug 18, 2026
Red Hat
Severity Moderate
Public date Aug 10, 2026
ENISA EUVD
Assigner Linux
Published Aug 10, 2026
Updated Aug 18, 2026
Exploited since n/a
EUVD-2026-55359