cbcvebase.
CVE-2021-4460
published 2025-10-01

CVE-2021-4460: In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix UBSAN shift-out-of-bounds warning If get_num_sdma_queues or…

PriorityP427high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.15%
4.7th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix UBSAN shift-out-of-bounds warning If get_num_sdma_queues or get_num_xgmi_sdma_queues is 0, we end up doing a shift operation where the number of bits shifted equals number of bits in the operand. This behaviour is undefined. Set num_sdma_queues or num_xgmi_sdma_queues to ULLONG_MAX, if the count is >= number of bits in the operand. Bug: https://gitlab.freedesktop.org/drm/amd/-/issues/1472

Affected

15 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.10.38-1 (bookworm)linux 5.10.38-1 (bookworm)
linuxlinux
linuxlinux>= 4a488a7ad71401169cecee75dc94bcce642e2c53 < 0c0356ef2498c1a250fe3846f30293f8287373090c0356ef2498c1a250fe3846f30293f828737309
linuxlinux>= 4a488a7ad71401169cecee75dc94bcce642e2c53 < 1874b0ef1426b873de94c61861e38f29a8df714c1874b0ef1426b873de94c61861e38f29a8df714c
linuxlinux>= 4a488a7ad71401169cecee75dc94bcce642e2c53 < 3fdc5182700910a685d23df57d65166e8556a2663fdc5182700910a685d23df57d65166e8556a266
linuxlinux>= 4a488a7ad71401169cecee75dc94bcce642e2c53 < 9069b1b542de8f3bbffef868aff41521b21485cf9069b1b542de8f3bbffef868aff41521b21485cf
linuxlinux>= 4a488a7ad71401169cecee75dc94bcce642e2c53 < 50e2fc36e72d4ad672032ebf646cecb48656efe050e2fc36e72d4ad672032ebf646cecb48656efe0
linuxlinux_kernel< 5.4.1185.4.118
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 5.11 < 5.11.205.11.20
linuxlinux_kernel>= 5.12 < 5.12.35.12.3
linuxlinux_kernel>= 5.5 < 5.10.365.10.36

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.