Answer in brief
CVE-2026-68257 records a Unknown severity vulnerability in drm/amdkfd: fix 32-bit overflow in CWSR total size calculation. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <b88ffe6593607364a8c06a48c6f29e55437cdf8e || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <abce3276c57e36c955627307469b9f009057a467 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <865532d54eb57b660b1cb1b0e1755776ce21b849 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <2b0386d4293920e690c0e017708f999b93cc729b || >=0 <6.12.101 || >=0 <6.18.42 || >=0 <7.1.6 | b88ffe6593607364a8c06a48c6f29e55437cdf8e, abce3276c57e36c955627307469b9f009057a467, 865532d54eb57b660b1cb1b0e1755776ce21b849, 2b0386d4293920e690c0e017708f999b93cc729b, 6.12.101, 6.18.42, 7.1.6 |
Published upstream
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 10, 2026
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: fix 32-bit overflow in CWSR total size calculation total_cwsr_size was computed in 32-bit before being used as a BO/SVM allocation size. With large ctx_save_restore_area_size and debug_memory_size multiplied by the XCC count, the product can wrap, yielding an undersized CWSR save area that firmware later overruns. Promote total_cwsr_size to u64 and use check_add_overflow()/ check_mul_overflow() in both kfd_queue_acquire_buffers() and kfd_queue_release_buffers(). (cherry picked from commit 319f7e13423ae3f486b9aea82f9ad2d6af0ee608)
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-68257 records a Unknown severity vulnerability in drm/amdkfd: fix 32-bit overflow in CWSR total size calculation. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <b88ffe6593607364a8c06a48c6f29e55437cdf8e || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <abce3276c57e36c955627307469b9f009057a467 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <865532d54eb57b660b1cb1b0e1755776ce21b849 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <2b0386d4293920e690c0e017708f999b93cc729b || >=0 <6.12.101 || >=0 <6.18.42 || >=0 <7.1.6 | b88ffe6593607364a8c06a48c6f29e55437cdf8e, abce3276c57e36c955627307469b9f009057a467, 865532d54eb57b660b1cb1b0e1755776ce21b849, 2b0386d4293920e690c0e017708f999b93cc729b, 6.12.101, 6.18.42, 7.1.6 |
Published upstream
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 10, 2026
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: fix 32-bit overflow in CWSR total size calculation total_cwsr_size was computed in 32-bit before being used as a BO/SVM allocation size. With large ctx_save_restore_area_size and debug_memory_size multiplied by the XCC count, the product can wrap, yielding an undersized CWSR save area that firmware later overruns. Promote total_cwsr_size to u64 and use check_add_overflow()/ check_mul_overflow() in both kfd_queue_acquire_buffers() and kfd_queue_release_buffers(). (cherry picked from commit 319f7e13423ae3f486b9aea82f9ad2d6af0ee608)
Quoted source text, attributed separately from HOL analysis.