Database/Kernel, userspace & hypervisor
Linux kernel amdkfd (KFD compute driver, /dev/kfd) (amd/amdkfd): A division by zero in the amdkfd (KFD compute driver
Impact
A division by zero in the amdkfd (KFD compute driver, /dev/kfd), reachable with attacker-influenced parameters. The kernel takes a divide fault and the node goes down, taking every co-resident job with it. Upstream fix: amd/amdkfd: enhance kfd process check in switch partition
Who can reach it
Local. Reachable by any process or container with /dev/kfd and /dev/dri/renderD* mapped in - which is every ROCm workload, including an unprivileged tenant pod. Not reachable over the network and not reachable from a container that has no GPU device node mapped in.
What to do
Kernel-side fix: this lands in mainline Linux and flows into distro kernels (RHEL/Rocky, Ubuntu HWE, SLES) and into AMD's out-of-tree DKMS amdgpu package shipped with ROCm. Patch the kernel or the DKMS module, then **reload the amdgpu module or reboot the node** - you cannot fix a running driver in place. Reloading amdgpu requires no process holding /dev/kfd or a render node, so in practice this is a cordon + drain + reboot per node. Plan it as a rolling maintenance across the fleet; there is no VBIOS flash, no SBIOS/AGESA step and no firmware update involved. Nodes running the ROCm DKMS stack often lag mainline by a release or two, so confirm the fix is actually present in the AMD driver version you deploy rather than assuming a new distro kernel covers it. Until the reboot window, the only real mitigation is to stop handing the render node to untrusted workloads - the device plugin has to be mapping /dev/dri/renderD* and /dev/kfd into the container for a tenant to reach this at all.
References
Related entries
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (amd/amdkfd): A NULL pointer dereference in the amdkfd (KFD computeCVE-2025-40310 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (amd/amdkfd)Unscored
- Linux kernel (virt/kvm): KVM blocked turning KVM_MEM_GUEST_MEMFD on for an existing memslot but not turning it off, andCVE-2025-68810 · Linux kernel (virt/kvm)High
- Linux kernel (drivers/iommu): In an SVA context the IOMMU walks and caches the CPU's page tables, and on x86 everyCVE-2025-71089 · Linux kernel (drivers/iommu)High
- Linux kernel (drivers/gpu/drm/xe): The observation-config ioctl dereferences the config object after releasing the lockCVE-2025-71099 · Linux kernel (drivers/gpu/drm/xe)High
- libvirt: integer overflow in NodeGetFreePages gives a local user heap corruption in the root daemonCVE-2026-18917 · libvirt (NodeGetFreePages RPC handler)High
- Linux KVM - irqfd routing type clobbered on deassign: Deassigning a KVM_IRQFD clobbers the irqfd's copy of theCVE-2026-23198 · Linux KVM - irqfd routing type clobbered on deassignHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.