KernelScan.io

HIGH

drm WatchId OOB

CVE-2026-45878

CVSS 7.8 / 10.0 NVD

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

KernelScan AI5.0MEDIUM

01

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix watch_id bounds checking in debug address watch v2 The address watch clear code receives watch_id as an unsigned value (u32), but some helper functions were using a signed int and checked bits by shifting with watch_id. If a very large watch_id is passed from userspace, it can be converted to a negative value. This can cause invalid shifts and may access memory outside the watch_points array. drm/amdkfd: Fix watch_id bounds checking in debug address watch v2 Fix this by checking that watch_id is within MAX_WATCH_ADDRESSES before using it. Also use BIT(watch_id) to test and clear bits safely. This keeps the behavior unchanged for valid watch IDs and avoids undefined behavior for invalid ones. Fixes the below: drivers/gpu/drm/amd/amdgpu/../amdkfd/kfd_debug.c:448 kfd_dbg_trap_clear_dev_address_watch() error: buffer overflow 'pdd->watch_points' 4 <= u32max user_rl='0-3,2147483648-u32max' uncapped drivers/gpu/drm/amd/amdgpu/../amdkfd/kfd_debug.c 433 int kfd_dbg_trap_clear_dev_address_watch(struct kfd_process_device *pdd, 434 uint32_t watch_id) 435 { 436 int r; 437 438 if (!kfd_dbg_owns_dev_watch_id(pdd, watch_id)) kfd_dbg_owns_dev_watch_id() doesn't check for negative values so if watch_id is larger than INT_MAX it leads to a buffer overflow. (Negative shifts are undefined). 439 return -EINVAL; 440 441 if (!pdd->dev->kfd->shared_resources.enable_mes) { 442 r = debug_lock_and_unmap(pdd->dev->dqm); 443 if (r) 444 return r; 445 } 446 447 amdgpu_gfx_off_ctrl(pdd->dev->adev, false); --> 448 pdd->watch_points[watch_id] = pdd->dev->kfd2kgd->clear_address_watch( 449 pdd->dev->adev, 450 watch_id); v2: (as per, Jonathan Kim) - Add early watch_id >= MAX_WATCH_ADDRESSES validation in the set path to match the clear path. - Drop the redundant bounds check in kfd_dbg_owns_dev_watch_id().

02

Engine v0.2.0

Risk summary

Local attackers with elevated GPU debugging privileges can trigger an out-of-bounds array access in the AMD KFD debug address watch interface by passing an oversized watch_id value. Because the invalid index exceeds INT_MAX and translates to a multi-gigabyte offset, the access hits unmapped kernel memory and results in a kernel panic. The primary impact is denial of service (system crash).

Affecteddrivers/gpu/drm/amd/amdkfd/kfd_debug.c (amdkfd)

Vulnerability analysis

The vulnerability exists in the AMD KFD debug address watch set/clear paths where a userspace-supplied watch_id (uint32_t) is used directly as an array index without adequate bounds validation. Although helper functions historically treated the ID as signed int, the array access in the main functions uses the original unsigned value. For watch_id values greater than INT_MAX, the signed helper checks are bypassed via undefined negative-shift behavior, and the subsequent access to pdd->watch_points[watch_id] uses an index of 2147483648 or higher against an array of only 4 elements. On 64-bit systems this produces a multi-gigabyte out-of-bounds write that immediately faults on unmapped pages, causing a kernel oops/panic. The fix adds an early bounds check (watch_id >= MAX_WATCH_ADDRESSES) in both the set and clear paths, and replaces unsafe manual bit-shifts with the BIT() macro.

03

BranchFixed inPatch commit
6.126.12.75a0d367e13db6
6.186.18.142b36c0c1bcbb
6.196.19.43c38a0f07aa2
6.66.6.128971bf8e61e9b
mainline7.05a19302cab5c