Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-43206

Опубликовано: 06 мая 2026
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() The kfd_event_page_set() function writes KFD_SIGNAL_EVENT_LIMIT * 8 bytes via memset without checking the buffer size parameter. This allows unprivileged userspace to trigger an out-of bounds kernel memory write by passing a small buffer, leading to potential privilege escalation.

A flaw was found in the Linux kernel's drm/amdkfd component. An unprivileged local user can exploit an out-of-bounds write vulnerability in the kfd_event_page_set() function. This occurs because the function writes data without properly validating the buffer size, allowing a small buffer to trigger a write beyond its allocated memory. Successful exploitation of this flaw could lead to potential privilege escalation.

Отчет

This Important vulnerability in the drm/amdkfd kernel module allows an unprivileged local attacker to trigger an out-of-bounds write, potentially leading to privilege escalation. Systems running Red Hat Enterprise Linux with AMD graphics drivers are affected.

Меры по смягчению последствий

To mitigate this issue, prevent the amdkfd kernel module from loading if it is not required. This can be achieved by blacklisting the module.

  1. Create a new file /etc/modprobe.d/blacklist-amdkfd.conf with the following content: blacklist amdkfd
  2. Regenerate the initramfs to ensure the blacklist is applied during boot: sudo dracut -f -v (for RHEL 8/9) sudo mkinitrd -f -v /boot/initramfs-$(uname -r).img $(uname -r) (for RHEL 7)
  3. Reboot the system for the changes to take effect. Note: Blacklisting the amdkfd module may impact functionality that relies on the AMD KFD driver, such as certain AMD GPU compute features. Evaluate the necessity of this module before applying the mitigation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kernelAffected
Red Hat Enterprise Linux 7kernelAffected
Red Hat Enterprise Linux 7kernel-rtAffected
Red Hat Enterprise Linux 9kernel-rtAffected
Red Hat Enterprise Linux 10kernelFixedRHSA-2026:5725120.08.2026
Red Hat Enterprise Linux 8kernel-rtFixedRHSA-2026:5576517.08.2026
Red Hat Enterprise Linux 8kernelFixedRHSA-2026:5576417.08.2026
Red Hat Enterprise Linux 9kernelFixedRHSA-2026:5725220.08.2026
Red Hat Enterprise Linux 9kernelFixedRHSA-2026:5725220.08.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2467156kernel: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set()

EPSS

Процентиль: 4%
0.00139
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() The kfd_event_page_set() function writes KFD_SIGNAL_EVENT_LIMIT * 8 bytes via memset without checking the buffer size parameter. This allows unprivileged userspace to trigger an out-of bounds kernel memory write by passing a small buffer, leading to potential privilege escalation.

CVSS3: 7.8
nvd
4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() The kfd_event_page_set() function writes KFD_SIGNAL_EVENT_LIMIT * 8 bytes via memset without checking the buffer size parameter. This allows unprivileged userspace to trigger an out-of bounds kernel memory write by passing a small buffer, leading to potential privilege escalation.

CVSS3: 7.8
debian
4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: d ...

CVSS3: 7.8
github
4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() The kfd_event_page_set() function writes KFD_SIGNAL_EVENT_LIMIT * 8 bytes via memset without checking the buffer size parameter. This allows unprivileged userspace to trigger an out-of bounds kernel memory write by passing a small buffer, leading to potential privilege escalation.

CVSS3: 7.8
fstec
7 месяцев назад

Уязвимость функции kfd_event_page_set() модуля drivers/gpu/drm/amd/amdkfd/kfd_events.c драйвера инфраструктуры прямого рендеринга (DRI) видеокарт AMD ядра операционной системы Linux, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 4%
0.00139
Низкий

7.8 High

CVSS3