Answer in brief
CVE-2026-80870 records a Unknown severity vulnerability in drm/amdkfd: Validate CRIU-restored IDs before idr_alloc. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=40e8a766a761f7fdc8530347527b344fddf6f1a8 <f8687018f24037056692c1e93c7d96cc72889d5b || >=40e8a766a761f7fdc8530347527b344fddf6f1a8 <89a75e3349c4fae28cbedc711bc924cbc6293da2 || >=40e8a766a761f7fdc8530347527b344fddf6f1a8 <085ea93bda71fee600cc12a17026598eb10dd1f9 || >=40e8a766a761f7fdc8530347527b344fddf6f1a8 <543ed0f61d56501cc585162da600bbedd7c08c0f || >=40e8a766a761f7fdc8530347527b344fddf6f1a8 <cb6311f25a096621ac7ffd91b50d1bb1cfb63a96 || >=40e8a766a761f7fdc8530347527b344fddf6f1a8 <85043dd49c2f51a37b22618168e3ae59ab92f0d6 | f8687018f24037056692c1e93c7d96cc72889d5b, 89a75e3349c4fae28cbedc711bc924cbc6293da2, 085ea93bda71fee600cc12a17026598eb10dd1f9, 543ed0f61d56501cc585162da600bbedd7c08c0f, cb6311f25a096621ac7ffd91b50d1bb1cfb63a96, 85043dd49c2f51a37b22618168e3ae59ab92f0d6 |
| Linux/Linuxgeneric | 5.18 | Not reported |
Published upstream
Sep 4, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 4, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 4, 2026
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Validate CRIU-restored IDs before idr_alloc The KFD CRIU restore flow restores previously saved object IDs from userspace. For event restore: kfd_criu_restore_event() -> create_signal_event() / create_other_event() -> allocate_event_notification_slot() -> idr_alloc(..., *restore_id, *restore_id + 1, ...) For BO restore: criu_restore_memory_of_gpu() -> idr_alloc(..., bo_priv->idr_handle, ...) In both cases, the restored ID comes from userspace-provided CRIU data. idr_alloc() expects the ID range values to fit within signed int limits. If a restored ID is larger than INT_MAX, it can trigger a WARN in the IDR layer. A kernel WARN is undesirable because it prints a warning trace and may cause a panic or reboot on systems with panic_on_warn enabled. Smatch reported these paths as allowing unchecked userspace values to reach idr_alloc(). Add INT_MAX validation before using restored IDs in: - kfd_criu_restore_event() - criu_restore_memory_of_gpu() If the restored ID is invalid, return -EINVAL. This prevents invalid restore data from reaching the IDR layer and avoids WARN-triggering paths, while keeping valid restore behavior unchanged.
Quoted source text, attributed separately from HOL analysis.