cbcvebase.
CVE-2026-45878
published 2026-05-27

CVE-2026-45878: In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix watch_id bounds checking in debug address watch v2 The address watch clear…

PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.18%
8.0th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix watch_id bounds checking in debug address watch v2 The address watch clear code receives watch_id as an unsigned value (u32), but some helper functions were using a signed int and checked bits by shifting with watch_id. If a very large watch_id is passed from userspace, it can be converted to a negative value. This can cause invalid shifts and may access memory outside the watch_points array. drm/amdkfd: Fix watch_id bounds checking in debug address watch v2 Fix this by checking that watch_id is within MAX_WATCH_ADDRESSES before using it. Also use BIT(watch_id) to test and clear bits safely. This keeps the behavior unchanged for valid watch IDs and avoids undefined behavior for invalid ones. Fixes the below: drivers/gpu/drm/amd/amdgpu/../amdkfd/kfd_debug.c:448 kfd_dbg_trap_clear_dev_address_watch() error: buffer overflow 'pdd->watch_points' 4 dev->kfd->shared_resources.enable_mes) { 442 r = debug_lock_and_unmap(pdd->dev->dqm); 443 if (r) 444 return r; 445 } 446 447 amdgpu_gfx_off_ctrl(pdd->dev->adev, false); --> 448 pdd->watch_points[watch_id] = pdd->dev->kfd2kgd->clear_address_watch( 449 pdd->dev->adev, 450 watch_id); v2: (as per, Jonathan Kim) - Add early watch_id >= MAX_WATCH_ADDRESSES validation in the set path to match the clear path. - Drop the redundant bounds check in kfd_dbg_owns_dev_watch_id().

Affected

41 ranges· showing 25
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= e0f85f4690d089cc1a60337decafb1acf7eec45e < 971bf8e61e9b4abaacf9b35eaf76ec222758f9d6971bf8e61e9b4abaacf9b35eaf76ec222758f9d6
linuxlinux>= e0f85f4690d089cc1a60337decafb1acf7eec45e < a0d367e13db63a6ed76ee0d0a8c3a58c1fa98488a0d367e13db63a6ed76ee0d0a8c3a58c1fa98488
linuxlinux>= e0f85f4690d089cc1a60337decafb1acf7eec45e < 2b36c0c1bcbbe15f6cfa9652084b3124c835a1502b36c0c1bcbbe15f6cfa9652084b3124c835a150
linuxlinux>= e0f85f4690d089cc1a60337decafb1acf7eec45e < 3c38a0f07aa2bfef2b219b1f045534ad93f85afd3c38a0f07aa2bfef2b219b1f045534ad93f85afd
linuxlinux>= e0f85f4690d089cc1a60337decafb1acf7eec45e < 5a19302cab5cec7ae7f1a60c619951e6c17d87425a19302cab5cec7ae7f1a60c619951e6c17d8742
linuxlinux_kernel>= 6.13 < 6.18.146.18.14
linuxlinux_kernel>= 6.19 < 6.19.46.19.4
linuxlinux_kernel>= 6.5 < 6.6.1286.6.128
linuxlinux_kernel>= 6.7 < 6.12.756.12.75
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-6.8
ubuntulinux-aws-fips
ubuntulinux-azure
ubuntulinux-azure-6.8
ubuntulinux-azure-fde
ubuntulinux-azure-fde-6.8
ubuntulinux-azure-fips
ubuntulinux-fips
ubuntulinux-gcp
ubuntulinux-gcp-6.8
ubuntulinux-gcp-fips
ubuntulinux-gke
ubuntulinux-gkeop

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.