CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's handling of the total size calculation for context save and restore (CWSR) areas, which can lead to a 32-bit overflow when large memory sizes are involved. This results in an undersized CWSR save area, potentially causing firmware overruns and system instability. Organizations using affected versions of the Linux kernel, particularly those leveraging AMD GPU compute capabilities, should prioritize addressing this issue to prevent potential exploitation and ensure system reliability.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: fix 32-bit overflow in CWSR total size calculation total_cwsr_size was computed in 32-bit before being used as a BO/SVM allocation size. With large ctx_save_restore_area_size and debug_memory_size multiplied by the XCC count, the product can wrap, yielding an undersized CWSR save area that firmware later overruns. Promote total_cwsr_size to u64 and use check_add_overflow()/ check_mul_overflow() in both kfd_queue_acquire_buffers() and kfd_queue_release_buffers(). (cherry picked from commit 319f7e13423ae3f486b9aea82f9ad2d6af0ee608)