Linux Kernel DRM AMDKFD OOB via nattr ioctl
CVE-2026-46197 Published on May 28, 2026
drm/amdkfd: validate SVM ioctl nattr against buffer size
In the Linux kernel, the following vulnerability has been resolved:
drm/amdkfd: validate SVM ioctl nattr against buffer size
Validate nattr field against the buffer size, preventing
out-of-bounds buffer access via user-controlled attribute count.
(cherry picked from commit 5eca8bfdfa456c3304ca77523718fe24254c172f)
Products Associated with CVE-2026-46197
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 42de677f79999791bee4e21be318c32d90ab62c6 and below 91c6dc5a41695d02dfc6299f106ac38a6c493e52 is affected.
- Version 42de677f79999791bee4e21be318c32d90ab62c6 and below ccd060b5c7cc75ae7e211c250b97c5b6272e7efc is affected.
- Version 42de677f79999791bee4e21be318c32d90ab62c6 and below db9530a9873a7c85d2266a922589ebcf427fa631 is affected.
- Version 42de677f79999791bee4e21be318c32d90ab62c6 and below 6abd3a4417cb73a7d0db7e25bf11fae1074bdba3 is affected.
- Version 42de677f79999791bee4e21be318c32d90ab62c6 and below 045e0ff208f0838a246c10204105126611b267a1 is affected.
- Version 5.14 is affected.
- Before 5.14 is unaffected.
- Version 6.6.140, <= 6.6.* is unaffected.
- Version 6.12.90, <= 6.12.* is unaffected.
- Version 6.18.32, <= 6.18.* is unaffected.
- Version 7.0.9, <= 7.0.* is unaffected.
- Version 7.1-rc2, <= * is unaffected.