CVE-2026-98176
Received Received - Intake

Integer Underflow in Linux Kernel AMDKFD Driver

Vulnerability report for CVE-2026-98176, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Avoid integer underflow with ffs in EOP ring size calc The low 6 bits of cp_hqd_eop_control store the base-2 logarithm of the EOP ring size. This was calculated as ffs(q->eop_ring_buffer_size / sizeof(unsigned int)) - 1 - 1 But ffs can in theory return 1 or 0, so this could underflow (although in practice the ring buffer size cannot be less than 4096). Change this to ffs(q->eop_ring_buffer_size / sizeof(unsigned int) / 4) using properties of logarithms. (cherry picked from commit 4f18c56630383c14bfc6b2d65f88f2f895d2121a)

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
Linux Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Linux Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Linux Linux 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves an integer underflow in the AMDKFD (AMD GPU kernel fusion driver) when calculating the EOP ring size. The issue occurs because the code incorrectly subtracts 1 twice from the result of ffs (find first set), which can theoretically return 0 or 1, leading to an underflow. The fix adjusts the calculation to prevent this.

Detection Guidance

This vulnerability is specific to the Linux kernel's drm/amdkfd driver and involves an integer underflow in EOP ring size calculation. Detection requires checking the kernel version and examining the affected driver code. No direct network detection commands are applicable. Use uname -a to check kernel version and grep for amdkfd in kernel logs or driver files.

Impact Analysis

This vulnerability could potentially cause system instability or crashes in systems using AMD GPUs with the affected Linux kernel component. However, the practical impact is likely minimal since the ring buffer size cannot be less than 4096, reducing the chance of exploitation.

Mitigation Strategies

Apply the latest kernel security updates from your Linux distribution. If using AMD GPU drivers, update the amdkfd module. Monitor kernel logs for related errors after updates. Avoid manual workarounds as the fix is integrated into patched kernels.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98176. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart