Database/Control plane, storage & DevOps
Linux HID/amd_sfh - shift out of bounds: A shift operation in the AMD Sensor Fusion Hub driver exceeds the maximum
UnscoredCVE-2023-53703Control plane, storage & DevOpscurated
Impact
A shift operation in the AMD Sensor Fusion Hub driver exceeds the maximum valid shift value, producing undefined behaviour in the kernel. Same story as the SFH use-after-free: low real exposure on a server, and a good reminder that unused autoloading drivers cost you something.
Who can reach it
Local, on hosts with amd_sfh loaded.
What to do
Distro kernel update plus reboot, or blacklist the module on server images and carry neither the bug nor the next one.
References
Related entries
- Linux perf/x86/amd - general protection fault from a NULL event on enable: A subtle race lets cpucCVE-2025-68798 · Linux perf/x86/amd - general protection fault from a NULL event on enableUnscored
- Apache CloudStack: unsanitized backup repository options inject OS commands onto the KVM hypervisor hostCVE-2026-47359 · Apache CloudStack NAS backup provider (addBackupRepository / updateBackupRepository)Unscored
- DMTF SPDM specification DSP0274 1.4 (FINISH transcript definition): A specification-level defect rather thanCVE-2026-61810 · DMTF SPDM specification DSP0274 1.4 (FINISH transcript definition)Unscored
- Linux x86/mm - broadcast TLB flush with PCID disabled: Booting with nopcid clears the PCID feature but broadcast TLBCVE-2026-64229 · Linux x86/mm - broadcast TLB flush with PCID disabledUnscored
- Linux crypto/ccp - SNP initialization on ioctl(SNP_COMMIT): The ccp driver initialised SNP from the SNP_COMMIT ioctlCVE-2026-64309 · Linux crypto/ccp - SNP initialization on ioctl(SNP_COMMIT)Unscored
- Linux iommu/amd - IRQ-unsafe locking in guest domain allocation: An IRQ-unsafe lock taken during AMD IOMMU guest domainCVE-2026-68347 · Linux iommu/amd - IRQ-unsafe locking in guest domain allocationUnscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.