PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-53143 Linux CVE debrief

CVE-2026-53143 is a HIGH severity vulnerability in the Linux kernel, specifically in the drm/amdkfd component. A buffer overflow occurs in SDMA queue checkpoint/restore on GFX11, allowing for potential memory corruption and information disclosure. The vulnerability has a CVSS score of 7. The issue arises from a copy-paste regression unique to v11, where the CP-compute variants of checkpoint_mqd/restore_mqd were incorrectly assigned for KFD_MQD_TYPE_SDMA queues. This results in a 1536-byte overflow when reading or writing to a 512-byte SDMA MQD buffer.

Vendor
Linux
Product
Unknown
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-25
Original CVE updated
2026-08-20
Advisory published
2026-06-25
Advisory updated
2026-08-20

Who should care

Linux kernel users and administrators, particularly those using GFX11-based systems, should be aware of this vulnerability. The vulnerability can be exploited locally, and its HIGH severity score indicates a significant risk. Users of affected systems should prioritize patching to prevent potential memory corruption and information disclosure.

Technical summary

The vulnerability is caused by a copy-paste error in the v11 MQD manager, which incorrectly assigned the CP-compute variants of checkpoint_mqd/restore_mqd for KFD_MQD_TYPE_SDMA queues. These functions use sizeof(struct v11_compute_mqd) (2048 bytes) instead of sizeof(struct v11_sdma_mqd) (512 bytes), leading to a 1536-byte overflow. During checkpoint, this allows 1536 bytes of adjacent GTT memory to be leaked to userspace. During restore, it can corrupt 1536 bytes of adjacent GTT memory, potentially affecting the ring buffer or neighboring MQDs.

Defensive priority

This vulnerability should be prioritized for patching due to its HIGH severity score and potential for memory corruption and information disclosure. Linux kernel users and administrators should apply patches as soon as possible to prevent exploitation.

Recommended defensive actions

  • Apply the official patch from the Linux kernel repository.
  • Review and update Linux kernel configurations to ensure the fix is applied.
  • Monitor system logs for potential exploitation attempts.
  • Perform regular vulnerability assessments to identify affected systems.
  • Consider implementing additional security controls, such as memory protection mechanisms.

Evidence notes

The CVE-2026-53143 vulnerability was introduced in the Linux kernel and affects the drm/amdkfd component. The vulnerability has a CVSS score of 7 and is classified as HIGH severity. The issue is caused by a copy-paste regression unique to v11, and the fix involves adding checkpoint_mqd_sdma() and restore_mqd_sdma() functions to properly handle the smaller v11_sdma_mqd structure.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-53143 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-53143

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-53143 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-53143

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/16dad1fb0d783a4008de30e32d0038c393de05b1

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/2c5b66c9b4057b385566940935ebc32f6e6ebfd2

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/352ea59028ea48a6fff77f19ae28f98f71946a80

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/d02f05d30f35b036f7cbaf72de634affb5b38ec6

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/d3efcadfe3eea5b4263b8f2d4463b15c9fc46a64

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/security/cve/CVE-2026-53143

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.