GHSA-wv9h-grcg-85wcMediumCVSS 5.5
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: add upper bound...
🔗 CVE IDs covered (1)
📋 Description
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: add upper bound check on user inputs in wait ioctl
Huge input values in amdgpu_userq_wait_ioctl can lead to a OOM and
could be exploited.
So check these input value against AMDGPU_USERQ_MAX_HANDLES
which is big enough value for genuine use cases and could
potentially avoid OOM.
v2: squash in Srini's fix
(cherry picked from commit fcec012c664247531aed3e662f4280ff804d1476)
🔗 References (5)
- https://nvd.nist.gov/vuln/detail/CVE-2026-43398
- https://git.kernel.org/stable/c/3cd93bc695b3456f26f5ed52753d9071da26202a
- https://git.kernel.org/stable/c/64ac7c09fc44985ec9bb6a9db740899fa40ca613
- https://git.kernel.org/stable/c/b1d10508da559da2e0ca9cca6505094a7df948e1
- https://github.com/advisories/GHSA-wv9h-grcg-85wc