CVE-2026-80870 (GCVE-0-2026-80870)

Vulnerability from cvelistv5 – Published: 2026-09-04 16:48 – Updated: 2026-09-04 16:48
VLAI
Title
drm/amdkfd: Validate CRIU-restored IDs before idr_alloc
Summary
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Validate CRIU-restored IDs before idr_alloc The KFD CRIU restore flow restores previously saved object IDs from userspace. For event restore: kfd_criu_restore_event() -> create_signal_event() / create_other_event() -> allocate_event_notification_slot() -> idr_alloc(..., *restore_id, *restore_id + 1, ...) For BO restore: criu_restore_memory_of_gpu() -> idr_alloc(..., bo_priv->idr_handle, ...) In both cases, the restored ID comes from userspace-provided CRIU data. idr_alloc() expects the ID range values to fit within signed int limits. If a restored ID is larger than INT_MAX, it can trigger a WARN in the IDR layer. A kernel WARN is undesirable because it prints a warning trace and may cause a panic or reboot on systems with panic_on_warn enabled. Smatch reported these paths as allowing unchecked userspace values to reach idr_alloc(). Add INT_MAX validation before using restored IDs in: - kfd_criu_restore_event() - criu_restore_memory_of_gpu() If the restored ID is invalid, return -EINVAL. This prevents invalid restore data from reaching the IDR layer and avoids WARN-triggering paths, while keeping valid restore behavior unchanged.
Severity
No CVSS data available.
Impacted products
Vendor Product Version
Linux Linux Affected: 40e8a766a761f7fdc8530347527b344fddf6f1a8 , < f8687018f24037056692c1e93c7d96cc72889d5b (git)
Affected: 40e8a766a761f7fdc8530347527b344fddf6f1a8 , < 89a75e3349c4fae28cbedc711bc924cbc6293da2 (git)
Affected: 40e8a766a761f7fdc8530347527b344fddf6f1a8 , < 085ea93bda71fee600cc12a17026598eb10dd1f9 (git)
Affected: 40e8a766a761f7fdc8530347527b344fddf6f1a8 , < 543ed0f61d56501cc585162da600bbedd7c08c0f (git)
Affected: 40e8a766a761f7fdc8530347527b344fddf6f1a8 , < cb6311f25a096621ac7ffd91b50d1bb1cfb63a96 (git)
Affected: 40e8a766a761f7fdc8530347527b344fddf6f1a8 , < 85043dd49c2f51a37b22618168e3ae59ab92f0d6 (git)
Create a notification for this product.
Linux Linux Affected: 5.18
Unaffected: 0 , < 5.18 (semver)
Unaffected: 6.1.178 , ≤ 6.1.* (semver)
Unaffected: 6.6.145 , ≤ 6.6.* (semver)
Unaffected: 6.12.97 , ≤ 6.12.* (semver)
Unaffected: 6.18.40 , ≤ 6.18.* (semver)
Unaffected: 7.1.5 , ≤ 7.1.* (semver)
Unaffected: 7.2 , ≤ * (original_commit_for_fix)
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/gpu/drm/amd/amdkfd/kfd_chardev.c",
            "drivers/gpu/drm/amd/amdkfd/kfd_events.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "f8687018f24037056692c1e93c7d96cc72889d5b",
              "status": "affected",
              "version": "40e8a766a761f7fdc8530347527b344fddf6f1a8",
              "versionType": "git"
            },
            {
              "lessThan": "89a75e3349c4fae28cbedc711bc924cbc6293da2",
              "status": "affected",
              "version": "40e8a766a761f7fdc8530347527b344fddf6f1a8",
              "versionType": "git"
            },
            {
              "lessThan": "085ea93bda71fee600cc12a17026598eb10dd1f9",
              "status": "affected",
              "version": "40e8a766a761f7fdc8530347527b344fddf6f1a8",
              "versionType": "git"
            },
            {
              "lessThan": "543ed0f61d56501cc585162da600bbedd7c08c0f",
              "status": "affected",
              "version": "40e8a766a761f7fdc8530347527b344fddf6f1a8",
              "versionType": "git"
            },
            {
              "lessThan": "cb6311f25a096621ac7ffd91b50d1bb1cfb63a96",
              "status": "affected",
              "version": "40e8a766a761f7fdc8530347527b344fddf6f1a8",
              "versionType": "git"
            },
            {
              "lessThan": "85043dd49c2f51a37b22618168e3ae59ab92f0d6",
              "status": "affected",
              "version": "40e8a766a761f7fdc8530347527b344fddf6f1a8",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/gpu/drm/amd/amdkfd/kfd_chardev.c",
            "drivers/gpu/drm/amd/amdkfd/kfd_events.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.18"
            },
            {
              "lessThan": "5.18",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.178",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.145",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.97",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.40",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "7.1.*",
              "status": "unaffected",
              "version": "7.1.5",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.178",
                  "versionStartIncluding": "5.18",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.145",
                  "versionStartIncluding": "5.18",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.97",
                  "versionStartIncluding": "5.18",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.40",
                  "versionStartIncluding": "5.18",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.1.5",
                  "versionStartIncluding": "5.18",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.2",
                  "versionStartIncluding": "5.18",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: Validate CRIU-restored IDs before idr_alloc\n\nThe KFD CRIU restore flow restores previously saved object IDs from\nuserspace.\n\nFor event restore:\n\n  kfd_criu_restore_event()\n      -\u003e create_signal_event() / create_other_event()\n          -\u003e allocate_event_notification_slot()\n              -\u003e idr_alloc(..., *restore_id, *restore_id + 1, ...)\n\nFor BO restore:\n\n  criu_restore_memory_of_gpu()\n      -\u003e idr_alloc(..., bo_priv-\u003eidr_handle, ...)\n\nIn both cases, the restored ID comes from userspace-provided CRIU data.\n\nidr_alloc() expects the ID range values to fit within signed int\nlimits. If a restored ID is larger than INT_MAX, it can trigger a WARN\nin the IDR layer.\n\nA kernel WARN is undesirable because it prints a warning trace and may\ncause a panic or reboot on systems with panic_on_warn enabled.\n\nSmatch reported these paths as allowing unchecked userspace values to\nreach idr_alloc().\n\nAdd INT_MAX validation before using restored IDs in:\n\n- kfd_criu_restore_event()\n- criu_restore_memory_of_gpu()\n\nIf the restored ID is invalid, return -EINVAL.\n\nThis prevents invalid restore data from reaching the IDR layer and\navoids WARN-triggering paths, while keeping valid restore behavior\nunchanged."
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-04T16:48:31.902Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/f8687018f24037056692c1e93c7d96cc72889d5b"
        },
        {
          "url": "https://git.kernel.org/stable/c/89a75e3349c4fae28cbedc711bc924cbc6293da2"
        },
        {
          "url": "https://git.kernel.org/stable/c/085ea93bda71fee600cc12a17026598eb10dd1f9"
        },
        {
          "url": "https://git.kernel.org/stable/c/543ed0f61d56501cc585162da600bbedd7c08c0f"
        },
        {
          "url": "https://git.kernel.org/stable/c/cb6311f25a096621ac7ffd91b50d1bb1cfb63a96"
        },
        {
          "url": "https://git.kernel.org/stable/c/85043dd49c2f51a37b22618168e3ae59ab92f0d6"
        }
      ],
      "title": "drm/amdkfd: Validate CRIU-restored IDs before idr_alloc",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-80870",
    "datePublished": "2026-09-04T16:48:31.902Z",
    "dateReserved": "2026-08-26T14:34:25.798Z",
    "dateUpdated": "2026-09-04T16:48:31.902Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "epss": {
      "cve": "CVE-2026-80870",
      "date": "2026-10-03",
      "epss": "0.00215",
      "percentile": "0.10763"
    },
    "nvd": {
      "cve": {
        "affected": [
          {
            "affectedData": [
              {
                "defaultStatus": "unaffected",
                "product": "Linux",
                "programFiles": [
                  "drivers/gpu/drm/amd/amdkfd/kfd_chardev.c",
                  "drivers/gpu/drm/amd/amdkfd/kfd_events.c"
                ],
                "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                "vendor": "Linux",
                "versions": [
                  {
                    "lessThan": "f8687018f24037056692c1e93c7d96cc72889d5b",
                    "status": "affected",
                    "version": "40e8a766a761f7fdc8530347527b344fddf6f1a8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "89a75e3349c4fae28cbedc711bc924cbc6293da2",
                    "status": "affected",
                    "version": "40e8a766a761f7fdc8530347527b344fddf6f1a8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "085ea93bda71fee600cc12a17026598eb10dd1f9",
                    "status": "affected",
                    "version": "40e8a766a761f7fdc8530347527b344fddf6f1a8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "543ed0f61d56501cc585162da600bbedd7c08c0f",
                    "status": "affected",
                    "version": "40e8a766a761f7fdc8530347527b344fddf6f1a8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "cb6311f25a096621ac7ffd91b50d1bb1cfb63a96",
                    "status": "affected",
                    "version": "40e8a766a761f7fdc8530347527b344fddf6f1a8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "85043dd49c2f51a37b22618168e3ae59ab92f0d6",
                    "status": "affected",
                    "version": "40e8a766a761f7fdc8530347527b344fddf6f1a8",
                    "versionType": "git"
                  }
                ]
              },
              {
                "defaultStatus": "affected",
                "product": "Linux",
                "programFiles": [
                  "drivers/gpu/drm/amd/amdkfd/kfd_chardev.c",
                  "drivers/gpu/drm/amd/amdkfd/kfd_events.c"
                ],
                "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                "vendor": "Linux",
                "versions": [
                  {
                    "status": "affected",
                    "version": "5.18"
                  },
                  {
                    "lessThan": "5.18",
                    "status": "unaffected",
                    "version": "0",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.1.*",
                    "status": "unaffected",
                    "version": "6.1.178",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.6.*",
                    "status": "unaffected",
                    "version": "6.6.145",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.12.*",
                    "status": "unaffected",
                    "version": "6.12.97",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.18.*",
                    "status": "unaffected",
                    "version": "6.18.40",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "7.1.*",
                    "status": "unaffected",
                    "version": "7.1.5",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "*",
                    "status": "unaffected",
                    "version": "7.2",
                    "versionType": "original_commit_for_fix"
                  }
                ]
              }
            ],
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
          }
        ],
        "cveTags": [],
        "descriptions": [
          {
            "lang": "en",
            "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: Validate CRIU-restored IDs before idr_alloc\n\nThe KFD CRIU restore flow restores previously saved object IDs from\nuserspace.\n\nFor event restore:\n\n  kfd_criu_restore_event()\n      -\u003e create_signal_event() / create_other_event()\n          -\u003e allocate_event_notification_slot()\n              -\u003e idr_alloc(..., *restore_id, *restore_id + 1, ...)\n\nFor BO restore:\n\n  criu_restore_memory_of_gpu()\n      -\u003e idr_alloc(..., bo_priv-\u003eidr_handle, ...)\n\nIn both cases, the restored ID comes from userspace-provided CRIU data.\n\nidr_alloc() expects the ID range values to fit within signed int\nlimits. If a restored ID is larger than INT_MAX, it can trigger a WARN\nin the IDR layer.\n\nA kernel WARN is undesirable because it prints a warning trace and may\ncause a panic or reboot on systems with panic_on_warn enabled.\n\nSmatch reported these paths as allowing unchecked userspace values to\nreach idr_alloc().\n\nAdd INT_MAX validation before using restored IDs in:\n\n- kfd_criu_restore_event()\n- criu_restore_memory_of_gpu()\n\nIf the restored ID is invalid, return -EINVAL.\n\nThis prevents invalid restore data from reaching the IDR layer and\navoids WARN-triggering paths, while keeping valid restore behavior\nunchanged."
          }
        ],
        "id": "CVE-2026-80870",
        "lastModified": "2026-09-04T17:16:58.860",
        "metrics": {},
        "published": "2026-09-04T17:16:58.860",
        "references": [
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/085ea93bda71fee600cc12a17026598eb10dd1f9"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/543ed0f61d56501cc585162da600bbedd7c08c0f"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/85043dd49c2f51a37b22618168e3ae59ab92f0d6"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/89a75e3349c4fae28cbedc711bc924cbc6293da2"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/cb6311f25a096621ac7ffd91b50d1bb1cfb63a96"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/f8687018f24037056692c1e93c7d96cc72889d5b"
          }
        ],
        "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "vulnStatus": "Received"
      }
    }
  }
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…