Out-of-Bounds Read Vulnerability in Linux Kernel Affecting AMD Graphics Drivers
CVE-2026-80747
Currently unrated
What is CVE-2026-80747?
The Linux kernel has a vulnerability in its AMD graphics driver components that stems from improper validation of subtype lengths in the CRAT (Compute Resource Affinity Table) parser. This oversight can lead to out-of-bounds reads when the function kfd_parse_subtype() interprets a malformed CRAT table which includes an oversized length field. By failing to confirm that the length remains within the valid boundaries of the associated image, it poses a risk for potential data exposure and instability. Proper validation measures have been added in recent updates to mitigate this issue.
Affected Version(s)
Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 6e7566ba4739dd573c331adde1c96690f7a567bd
Linux 0 < 7.1.10