Linux kernel amdkfd: user-controlled metadata size lets any render-group user force a huge kernel allocation
Impact
The AMDKFD_IOC_GET_DMABUF_INFO ioctl allocated the buffer for returning buffer-object metadata using a size supplied entirely by user space. Any process able to open the ROCm compute device and issue the ioctl could request an order-MAX allocation (the commit log cites 2 GiB) and drive the kernel into OOM in kernel context. On a shared AMD GPU node that is a single-tenant denial of service against the whole host: every other training or inference job on the node is collateral, and the node has to be drained and rebooted rather than just having one pod killed. The fix makes the driver determine the real metadata size itself and ask user space to retry with a correctly sized buffer instead of trusting the request.
Who can reach it
Local user with access to the AMD KFD compute device - in practice any tenant holding /dev/kfd, i.e. any container that has been given an AMD GPU. No special privilege beyond render-group membership, and no authentication beyond having a GPU pod on the node.
What to do
Pick up the fix from the stable trees linked in the record (four backports) and run a patched kernel. This is a kernel driver change, so it means rebooting each AMD GPU node after draining its workloads; there is no module-reload path that is safe while jobs hold KFD contexts. Until then, the exposure follows GPU device access - tenants that do not get /dev/kfd cannot reach the ioctl.
References
Related entries
- Linux kernel amdgpu: unclamped write position in the vBIOS update sysfs attribute overflows the bufferCVE-2026-97425 · Linux kernel amdgpu (vBIOS update sysfs bin attribute)Unscored
- Linux kernel amdgpu powerplay: pp_table sysfs write memcpys up to PAGE_SIZE into a smaller heap bufferCVE-2026-97427 · Linux kernel amdgpu powerplay (pp_dpm_set_pp_table sysfs store)Unscored
- Linux kernel drm/amdgpu: unbounded VBIOS GPIO I2C entry count overruns adev->i2c_bus[]CVE-2026-97493 · Linux kernel amdgpu VBIOS GPIO I2C table parsing (drm/amdgpu)Unscored
- Linux amdgpu: PSP firmware image copied into the 1 MiB private buffer without a size checkCVE-2026-97494 · Linux kernel drm/amdgpu (PSP firmware private buffer, psp_copy_fw)Unscored
- Linux amdkfd: caller-supplied doorbell id is not bounds checked in allocate_doorbellCVE-2026-97495 · Linux kernel drm/amdkfd (allocate_doorbell, caller-supplied doorbell id)Unscored
- Linux amdgpu userq: MQD and firmware buffer objects can be evicted, hanging the GPU nodeCVE-2026-97498 · Linux kernel drm/amdgpu user queues (MQD and firmware BO eviction)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.