{"api_version":"1","generated_at":"2026-08-15T08:45:06+00:00","cve":"CVE-2026-74357","urls":{"html":"https://cve.report/CVE-2026-74357","api":"https://cve.report/api/cve/CVE-2026-74357.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-74357","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-74357"},"summary":{"title":"drm/amdgpu: fix KASAN slab-out-of-bounds in amdgpu_coredump ring dump","description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: fix KASAN slab-out-of-bounds in amdgpu_coredump ring dump\n\nThe ring content dump in amdgpu_coredump() uses two separate loops over\nadev->rings[]: the first counts rings with unsignalled fences to size\nthe allocation, and the second copies ring data into the allocated\nbuffers.\n\nBoth loops use the same condition to skip rings:\n\n    atomic_read(&ring->fence_drv.last_seq) == ring->fence_drv.sync_seq\n\nBecause last_seq is an atomic that is updated concurrently by the fence\nsignalling path, additional rings may appear unsignalled in the second\nloop that were signalled during the first. When this happens, idx\nexceeds the allocated ring_count and the store to coredump->rings[idx]\nwrites past the end of the kcalloc-ed buffer.\n\nThis was found during IGT stressful test amd_queue_reset which\ntriggers random GPU resets. The OVERSIZE subtest\n(CMD_STREAM_EXEC_INVALID_PACKET_LENGTH_OVERSIZE on GFX ring) provokes\na ring timeout and subsequent coredump, which hits the race between\nthe counting and copying loops. The failure is non-deterministic and\ndepends on fence signalling timing during the reset.\n\nKASAN log:\n\n  BUG: KASAN: slab-out-of-bounds in amdgpu_coredump+0x1274/0x12f0 [amdgpu]\n  Write of size 4 at addr ffff888106154258 by task kworker/u128:5/23625\n  CPU: 16 UID: 0 PID: 23625 Comm: kworker/u128:5 Not tainted 6.19.0+ #35\n  Workqueue: amdgpu-reset-dev drm_sched_job_timedout [gpu_sched]\n  Call Trace:\n   <TASK>\n   dump_stack_lvl+0xa5/0x110\n   print_report+0xd1/0x660\n   kasan_report+0xf3/0x130\n   __asan_report_store4_noabort+0x17/0x30\n   amdgpu_coredump+0x1274/0x12f0 [amdgpu]\n   amdgpu_job_timedout+0xef0/0x16c0 [amdgpu]\n   drm_sched_job_timedout+0x194/0x5c0 [gpu_sched]\n   process_one_work+0x84b/0x1990\n   worker_thread+0x6b8/0x11b0\n   </TASK>\n\n  Allocated by task 23625:\n   kasan_save_stack+0x39/0x70\n   __kasan_kmalloc+0xc3/0xd0\n   __kmalloc_noprof+0x2ec/0x910\n   amdgpu_coredump+0x5c5/0x12f0 [amdgpu]\n   amdgpu_job_timedout+0xef0/0x16c0 [amdgpu]\n\n  The buggy address belongs to the object at ffff888106154200\n   which belongs to the cache kmalloc-rnd-09-96 of size 96\n  The buggy address is located 16 bytes to the right of\n   allocated 72-byte region [ffff888106154200, ffff888106154248)\n\n72 bytes = 3 * sizeof(struct amdgpu_coredump_ring), so ring_count was 3\nbut idx reached 3+, writing ring_index (at struct offset 16) 16 bytes\npast the allocation.\n\nFix by adding an idx < ring_count guard to the copy loop so it cannot\nexceed the allocated count even when the fence state changes between\nthe two passes.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-08-15 06:22:37","updated_at":"2026-08-15 06:22:37"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/08ac3a7879d300302a1927ce2038629539a37f8b","name":"https://git.kernel.org/stable/c/08ac3a7879d300302a1927ce2038629539a37f8b","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/efb1dadaeb897b22b9e118d398d0f41e70e9ccca","name":"https://git.kernel.org/stable/c/efb1dadaeb897b22b9e118d398d0f41e70e9ccca","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-74357","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74357","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected eea85914d15bfe3bdf9f8f80a479f0dee0aa7d73 efb1dadaeb897b22b9e118d398d0f41e70e9ccca git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected eea85914d15bfe3bdf9f8f80a479f0dee0aa7d73 08ac3a7879d300302a1927ce2038629539a37f8b git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 7.1","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1.5 7.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2-rc1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/gpu/drm/amd/amdgpu/amdgpu_dev_coredump.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"efb1dadaeb897b22b9e118d398d0f41e70e9ccca","status":"affected","version":"eea85914d15bfe3bdf9f8f80a479f0dee0aa7d73","versionType":"git"},{"lessThan":"08ac3a7879d300302a1927ce2038629539a37f8b","status":"affected","version":"eea85914d15bfe3bdf9f8f80a479f0dee0aa7d73","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/gpu/drm/amd/amdgpu/amdgpu_dev_coredump.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"7.1"},{"lessThan":"7.1","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"7.1.*","status":"unaffected","version":"7.1.5","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2-rc1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.5","versionStartIncluding":"7.1","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2-rc1","versionStartIncluding":"7.1","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: fix KASAN slab-out-of-bounds in amdgpu_coredump ring dump\n\nThe ring content dump in amdgpu_coredump() uses two separate loops over\nadev->rings[]: the first counts rings with unsignalled fences to size\nthe allocation, and the second copies ring data into the allocated\nbuffers.\n\nBoth loops use the same condition to skip rings:\n\n    atomic_read(&ring->fence_drv.last_seq) == ring->fence_drv.sync_seq\n\nBecause last_seq is an atomic that is updated concurrently by the fence\nsignalling path, additional rings may appear unsignalled in the second\nloop that were signalled during the first. When this happens, idx\nexceeds the allocated ring_count and the store to coredump->rings[idx]\nwrites past the end of the kcalloc-ed buffer.\n\nThis was found during IGT stressful test amd_queue_reset which\ntriggers random GPU resets. The OVERSIZE subtest\n(CMD_STREAM_EXEC_INVALID_PACKET_LENGTH_OVERSIZE on GFX ring) provokes\na ring timeout and subsequent coredump, which hits the race between\nthe counting and copying loops. The failure is non-deterministic and\ndepends on fence signalling timing during the reset.\n\nKASAN log:\n\n  BUG: KASAN: slab-out-of-bounds in amdgpu_coredump+0x1274/0x12f0 [amdgpu]\n  Write of size 4 at addr ffff888106154258 by task kworker/u128:5/23625\n  CPU: 16 UID: 0 PID: 23625 Comm: kworker/u128:5 Not tainted 6.19.0+ #35\n  Workqueue: amdgpu-reset-dev drm_sched_job_timedout [gpu_sched]\n  Call Trace:\n   <TASK>\n   dump_stack_lvl+0xa5/0x110\n   print_report+0xd1/0x660\n   kasan_report+0xf3/0x130\n   __asan_report_store4_noabort+0x17/0x30\n   amdgpu_coredump+0x1274/0x12f0 [amdgpu]\n   amdgpu_job_timedout+0xef0/0x16c0 [amdgpu]\n   drm_sched_job_timedout+0x194/0x5c0 [gpu_sched]\n   process_one_work+0x84b/0x1990\n   worker_thread+0x6b8/0x11b0\n   </TASK>\n\n  Allocated by task 23625:\n   kasan_save_stack+0x39/0x70\n   __kasan_kmalloc+0xc3/0xd0\n   __kmalloc_noprof+0x2ec/0x910\n   amdgpu_coredump+0x5c5/0x12f0 [amdgpu]\n   amdgpu_job_timedout+0xef0/0x16c0 [amdgpu]\n\n  The buggy address belongs to the object at ffff888106154200\n   which belongs to the cache kmalloc-rnd-09-96 of size 96\n  The buggy address is located 16 bytes to the right of\n   allocated 72-byte region [ffff888106154200, ffff888106154248)\n\n72 bytes = 3 * sizeof(struct amdgpu_coredump_ring), so ring_count was 3\nbut idx reached 3+, writing ring_index (at struct offset 16) 16 bytes\npast the allocation.\n\nFix by adding an idx < ring_count guard to the copy loop so it cannot\nexceed the allocated count even when the fence state changes between\nthe two passes."}],"providerMetadata":{"dateUpdated":"2026-08-15T05:58:42.116Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/efb1dadaeb897b22b9e118d398d0f41e70e9ccca"},{"url":"https://git.kernel.org/stable/c/08ac3a7879d300302a1927ce2038629539a37f8b"}],"title":"drm/amdgpu: fix KASAN slab-out-of-bounds in amdgpu_coredump ring dump","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-74357","datePublished":"2026-08-15T05:58:42.116Z","dateReserved":"2026-08-15T05:44:03.887Z","dateUpdated":"2026-08-15T05:58:42.116Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-15 06:22:37","lastModifiedDate":"2026-08-15 06:22:37","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"74357","Ordinal":"1","Title":"drm/amdgpu: fix KASAN slab-out-of-bounds in amdgpu_coredump ring","CVE":"CVE-2026-74357","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"74357","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: fix KASAN slab-out-of-bounds in amdgpu_coredump ring dump\n\nThe ring content dump in amdgpu_coredump() uses two separate loops over\nadev->rings[]: the first counts rings with unsignalled fences to size\nthe allocation, and the second copies ring data into the allocated\nbuffers.\n\nBoth loops use the same condition to skip rings:\n\n    atomic_read(&ring->fence_drv.last_seq) == ring->fence_drv.sync_seq\n\nBecause last_seq is an atomic that is updated concurrently by the fence\nsignalling path, additional rings may appear unsignalled in the second\nloop that were signalled during the first. When this happens, idx\nexceeds the allocated ring_count and the store to coredump->rings[idx]\nwrites past the end of the kcalloc-ed buffer.\n\nThis was found during IGT stressful test amd_queue_reset which\ntriggers random GPU resets. The OVERSIZE subtest\n(CMD_STREAM_EXEC_INVALID_PACKET_LENGTH_OVERSIZE on GFX ring) provokes\na ring timeout and subsequent coredump, which hits the race between\nthe counting and copying loops. The failure is non-deterministic and\ndepends on fence signalling timing during the reset.\n\nKASAN log:\n\n  BUG: KASAN: slab-out-of-bounds in amdgpu_coredump+0x1274/0x12f0 [amdgpu]\n  Write of size 4 at addr ffff888106154258 by task kworker/u128:5/23625\n  CPU: 16 UID: 0 PID: 23625 Comm: kworker/u128:5 Not tainted 6.19.0+ #35\n  Workqueue: amdgpu-reset-dev drm_sched_job_timedout [gpu_sched]\n  Call Trace:\n   <TASK>\n   dump_stack_lvl+0xa5/0x110\n   print_report+0xd1/0x660\n   kasan_report+0xf3/0x130\n   __asan_report_store4_noabort+0x17/0x30\n   amdgpu_coredump+0x1274/0x12f0 [amdgpu]\n   amdgpu_job_timedout+0xef0/0x16c0 [amdgpu]\n   drm_sched_job_timedout+0x194/0x5c0 [gpu_sched]\n   process_one_work+0x84b/0x1990\n   worker_thread+0x6b8/0x11b0\n   </TASK>\n\n  Allocated by task 23625:\n   kasan_save_stack+0x39/0x70\n   __kasan_kmalloc+0xc3/0xd0\n   __kmalloc_noprof+0x2ec/0x910\n   amdgpu_coredump+0x5c5/0x12f0 [amdgpu]\n   amdgpu_job_timedout+0xef0/0x16c0 [amdgpu]\n\n  The buggy address belongs to the object at ffff888106154200\n   which belongs to the cache kmalloc-rnd-09-96 of size 96\n  The buggy address is located 16 bytes to the right of\n   allocated 72-byte region [ffff888106154200, ffff888106154248)\n\n72 bytes = 3 * sizeof(struct amdgpu_coredump_ring), so ring_count was 3\nbut idx reached 3+, writing ring_index (at struct offset 16) 16 bytes\npast the allocation.\n\nFix by adding an idx < ring_count guard to the copy loop so it cannot\nexceed the allocated count even when the fence state changes between\nthe two passes.","Type":"Description","Title":"drm/amdgpu: fix KASAN slab-out-of-bounds in amdgpu_coredump ring"}]}}}