CVE-2026-53143
published 2026-06-25CVE-2026-53143: In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 The v11 MQD…
PriorityP342high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.14%
3.9th percentile
In the Linux kernel, the following vulnerability has been resolved:
drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11
The v11 MQD manager incorrectly assigned the CP-compute variants of
checkpoint_mqd/restore_mqd for KFD_MQD_TYPE_SDMA queues. These functions
use sizeof(struct v11_compute_mqd) (2048 bytes) instead of sizeof(struct
v11_sdma_mqd) (512 bytes), causing a 1536-byte overflow.
During CRIU checkpoint of an SDMA queue on Navi3x:
- checkpoint_mqd() reads 2048 bytes from a 512-byte SDMA MQD buffer,
leaking 1536 bytes of adjacent GTT memory to userspace
During CRIU restore:
- restore_mqd() writes 2048 bytes into a 512-byte SDMA MQD buffer,
corrupting 1536 bytes of adjacent GTT memory (often the ring buffer
or neighboring MQDs)
This is a copy-paste regression unique to v11. All other ASIC backends
(cik, vi, v9, v10, v12) correctly use the SDMA-specific variants.
Add checkpoint_mqd_sdma() and restore_mqd_sdma() functions that properly
handle the smaller v11_sdma_mqd structure, matching the pattern used in
other MQD managers.
(cherry picked from commit 6fa41db7ffdec97d62433adf03b7b9b759af8c2c)
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | — | — |
| linux | linux | >= cc009e613de6560eb499f8bc92c80a737752cb30 < 16dad1fb0d783a4008de30e32d0038c393de05b1 | 16dad1fb0d783a4008de30e32d0038c393de05b1 |
| linux | linux | >= cc009e613de6560eb499f8bc92c80a737752cb30 < 2c5b66c9b4057b385566940935ebc32f6e6ebfd2 | 2c5b66c9b4057b385566940935ebc32f6e6ebfd2 |
| linux | linux | >= cc009e613de6560eb499f8bc92c80a737752cb30 < d3efcadfe3eea5b4263b8f2d4463b15c9fc46a64 | d3efcadfe3eea5b4263b8f2d4463b15c9fc46a64 |
| linux | linux | >= cc009e613de6560eb499f8bc92c80a737752cb30 < d02f05d30f35b036f7cbaf72de634affb5b38ec6 | d02f05d30f35b036f7cbaf72de634affb5b38ec6 |
| linux | linux | >= cc009e613de6560eb499f8bc92c80a737752cb30 < 352ea59028ea48a6fff77f19ae28f98f71946a80 | 352ea59028ea48a6fff77f19ae28f98f71946a80 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 5.19 < 6.6.143 | 6.6.143 |
| linux | linux_kernel | >= 6.13 < 6.18.36 | 6.18.36 |
| linux | linux_kernel | >= 6.19 < 7.0.13 | 7.0.13 |
| linux | linux_kernel | >= 6.7 < 6.12.94 | 6.12.94 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Linux Kernel up to 6.6.142/6.12.93/6.18.35/7.0.12 drm checkpoint_mqd buffer overflow (Nessus ID 323590 / WID-SEC-2026-2077)
vuldb·2026-06-29
CVE-2026-53143 [CRITICAL] Linux Kernel up to 6.6.142/6.12.93/6.18.35/7.0.12 drm checkpoint_mqd buffer overflow (Nessus ID 323590 / WID-SEC-2026-2077)
A vulnerability identified as critical has been detected in Linux Kernel up to 6.6.142/6.12.93/6.18.35/7.0.12. This affects the function checkpoint_mqd of the component drm. Performing a manipulation results in buffer overflow.
This vulnerability was named CVE-2026-53143. The attack needs to be approached within the local network. There is no available exploit.
You should upgrade the affected component.
GHSA
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 The v11 MQD manager incorrectly assigned the CP-compute
ghsa_unreviewed·2026-06-25
CVE-2026-53143 In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 The v11 MQD manager incorrectly assigned the CP-compute
In the Linux kernel, the following vulnerability has been resolved:
drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11
The v11 MQD manager incorrectly assigned the CP-compute variants of
checkpoint_mqd/restore_mqd for KFD_MQD_TYPE_SDMA queues. These functions
use sizeof(struct v11_compute_mqd) (2048 bytes) instead of sizeof(struct
v11_sdma_mqd) (512 bytes), causing a 1536-byte overflow.
During CRIU checkpoint of an SDMA queue on Navi3x:
- checkpoint_mqd() reads 2048 bytes from a 512-byte SDMA MQD buffer,
leaking 1536 bytes of adjacent GTT memory to userspace
During CRIU restore:
- restore_mqd() writes 2048 bytes into a 512-byte SDMA MQD buffer,
corrupting 1536 bytes of adjacent GTT memory (often the ring buffer
or neighboring MQDs)
This is a copy-paste regressio
Red Hat
kernel: drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11
vendor_redhat·2026-06-25·CVSS 7.0
CVE-2026-53143 [HIGH] CWE-131 kernel: drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11
kernel: drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11
A flaw was found in the Linux kernel's AMD KFD (Kernel Fusion Driver) component. This buffer overflow vulnerability occurs due to incorrect memory buffer handling during CRIU (Checkpoint/Restore in User-space) operations on SDMA (System Direct Memory Access) queues. A local attacker can exploit this flaw during CRIU restore operations, which can lead to memory corruption in adjacent kernel memory, potentially impacting system stability or leading to further compromise. Additionally, during CRIU checkpoint operations, this vulnerability can result in information disclosure of adjacent kernel memory to userspace.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/16dad1fb0d783a4008de30e32d0038c393de05b1https://git.kernel.org/stable/c/2c5b66c9b4057b385566940935ebc32f6e6ebfd2https://git.kernel.org/stable/c/352ea59028ea48a6fff77f19ae28f98f71946a80https://git.kernel.org/stable/c/d02f05d30f35b036f7cbaf72de634affb5b38ec6https://git.kernel.org/stable/c/d3efcadfe3eea5b4263b8f2d4463b15c9fc46a64https://access.redhat.com/security/cve/CVE-2026-53143https://bugzilla.redhat.com/show_bug.cgi?id=2492719https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53143.json
2026-06-25
Published