GPU VulnDB

Database/NVIDIA / GPU stack

Linux amdkfd: caller-supplied doorbell id is not bounds checked in allocate_doorbell

UnscoredCVE-2026-97495NVIDIA / GPU stackcurated

Impact

allocate_doorbell lets the caller pin a queue to a specific doorbell id - the path CRIU checkpoint/restore uses - and that id was never compared against KFD_MAX_NUM_OF_QUEUES_PER_PROCESS. An out-of-range id indexes past the per-process doorbell tracking, giving out-of-bounds kernel access driven by a value that arrives from userspace through the KFD ioctl interface. This is the compute path of the AMD GPU driver, so on a shared ROCm node any process holding /dev/kfd - which is exactly what a GPU pod holds - touches it. The record carries no CVSS score, and it does not state whether the out-of-bounds access is a read, a write, or both.

Who can reach it

Local user or container with a /dev/kfd file descriptor, i.e. any tenant granted an AMD GPU. No additional privilege is described.

What to do

Update to a stable kernel carrying the KFD_MAX_NUM_OF_QUEUES_PER_PROCESS bounds check (three stable commits listed) and reboot the node; amdgpu/amdkfd cannot be swapped under live GPU workloads, so schedule a drain and reboot per node. No fixed distro version is given in the record.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.