Linux amdkfd: caller-supplied doorbell id is not bounds checked in allocate_doorbell
Impact
allocate_doorbell lets the caller pin a queue to a specific doorbell id - the path CRIU checkpoint/restore uses - and that id was never compared against KFD_MAX_NUM_OF_QUEUES_PER_PROCESS. An out-of-range id indexes past the per-process doorbell tracking, giving out-of-bounds kernel access driven by a value that arrives from userspace through the KFD ioctl interface. This is the compute path of the AMD GPU driver, so on a shared ROCm node any process holding /dev/kfd - which is exactly what a GPU pod holds - touches it. The record carries no CVSS score, and it does not state whether the out-of-bounds access is a read, a write, or both.
Who can reach it
Local user or container with a /dev/kfd file descriptor, i.e. any tenant granted an AMD GPU. No additional privilege is described.
What to do
Update to a stable kernel carrying the KFD_MAX_NUM_OF_QUEUES_PER_PROCESS bounds check (three stable commits listed) and reboot the node; amdgpu/amdkfd cannot be swapped under live GPU workloads, so schedule a drain and reboot per node. No fixed distro version is given in the record.
References
Related entries
- Linux amdgpu userq: MQD and firmware buffer objects can be evicted, hanging the GPU nodeCVE-2026-97498 · Linux kernel drm/amdgpu user queues (MQD and firmware BO eviction)Unscored
- Linux drm/xe: NULL dereference when freeing a devcoredump snapshot that was never populatedCVE-2026-97519 · Linux kernel drm/xe (devcoredump snapshot cleanup)Unscored
- GPU / accelerator firmware (VBIOS, GSP, NVSwitch): GPU-resident firmware sits below the host OS and is not coveredNCVD-0000-012-gpu-accelerator-firmware-vbios-g · GPU / accelerator firmware (VBIOS, GSP, NVSwitch)Unscored
- NVIDIA Multi-Instance GPU (MIG) partitioning: MIG gives each instance its own SM slice, L2 slice, memory slice andNCVD-2020-001-nvidia-multi-instance-gpu-mig-pa · NVIDIA Multi-Instance GPU (MIG) partitioningUnscored
- NVIDIA Multi-Instance GPU (MIG) partitioning: MIG gives each instance its own SM slice, L2 slice, memory slice andNCVD-2020-003-nvidia-multi-instance-gpu-mig-pa · NVIDIA Multi-Instance GPU (MIG) partitioningUnscored
- Integrated GPU graphics data compression (Intel, AMD, Apple, Arm, Qualcomm, NVIDIA): GPUs apply data-dependent losslessNCVD-2023-003-integrated-gpu-graphics-data-com · Integrated GPU graphics data compression (Intel, AMD, Apple, Arm, Qualcomm, NVIDIA)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.