OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-97497

HIGH · CVSS 7.8 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

A bounds-checking vulnerability in the Linux kernel's `allocate_sdma_queue` function could allow an attacker to specify an out-of-bounds sdma queue ID, potentially leading to memory corruption or denial of service. This issue primarily affects systems utilizing the amdkfd driver for AMD GPUs, particularly those employing CRIU for process checkpointing and restoration. Organizations using affected Linux distributions with AMD hardware should prioritize patching to mitigate potential exploitation risks.

CVE
CVE-2026-97497
Severity
HIGH
CVSS
7.8
EPSS
0.13%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Check bounds for allocate_sdma_queue restore_sdma_id allocate_sdma_queue has an option where the sdma queue id can be specified (used by CRIU). We weren't bounds-checking that value. Confirm it's less than the maximum number of queues.