In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: validate SVM ioctl nattr against buffer size Validate nattr field against the buffer size, preventing out-of-bounds buffer access via user-controlled attribute count. (cherry picked from commit 5eca8bfdfa456c3304ca77523718fe24254c172f)
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2026052831-CVE-2026-46197-2b7a@gregkh/T