Bug 2516740 (CVE-2026-72449) - CVE-2026-72449 kernel: drm/amdkfd: fix list_del corruption in kfd_criu_resume_svm
Summary: CVE-2026-72449 kernel: drm/amdkfd: fix list_del corruption in kfd_criu_resume...
Keywords:
Status: NEW
Alias: CVE-2026-72449
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-15 06:28 UTC by OSIDB Bzimport
Modified: 2026-08-19 17:08 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-15 06:28:36 UTC
In the Linux kernel, the following vulnerability has been resolved:

drm/amdkfd: fix list_del corruption in kfd_criu_resume_svm

The cleanup tail of kfd_criu_resume_svm() walks
svms->criu_svm_metadata_list and kfree()s each struct criu_svm_metadata
without removing it from the list. The list head is left pointing at
freed kmalloc-96 objects.

A second AMDKFD_IOC_CRIU_OP from the same process re-enters: list_empty()
reads the dangling ->next (use-after-free), the loop walks freed entries,
and each is kfree()'d again (double-free). This is reachable by an
unprivileged render-group user via /dev/kfd with no capabilities required.

Add list_del() before the kfree() so the list is properly emptied. The
list_for_each_entry_safe() iterator already caches the next pointer, so
unlinking during the walk is safe.

(cherry picked from commit 6322d278a298e2c1430b9d2697743d3a04b788b1)


Note You need to log in before you can comment on or make changes to this bug.