PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-72449 Linux CVE debrief

The Linux kernel's drm/amdkfd component contains a vulnerability in the kfd_criu_resume_svm function, leading to a double-free error. This occurs because the function walks the svms->criu_svm_metadata_list and kfree()s each struct criu_svm_metadata without removing it from the list, causing a use-after-free condition when the list is traversed again. The vulnerability is reachable by an unprivileged render-group user via /dev/kfd with no capabilities required. Affected deployments should be identified and prioritized for patching based on risk and exposure. Compensating controls, such as restricting access to /dev/kfd, may be necessary while patches are being applied. Monitoring for suspicious activity related to the drm/amdkfd component is also recommended. Asset inventory and rollback/change windows should be considered in remediation efforts. Source tracking and exposure reviews are crucial for ensuring comprehensive mitigation.

Vendor
Linux
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-15
Original CVE updated
2026-08-15
Advisory published
2026-08-15
Advisory updated
2026-08-15

Who should care

Users and administrators of systems with the affected Linux kernel version should apply the patch to prevent exploitation of this vulnerability. This includes operators, platform administrators, and security teams responsible for vulnerability management and patching. The vulnerability's impact is limited to systems with the affected component and an unprivileged user can exploit it, which requires prompt attention and mitigation efforts to prevent potential security breaches. Affected deployments should be identified and prioritized for patching based on risk and exposure. Compensating controls, such as restricting access to /dev/kfd, may be necessary while patches are being applied. Monitoring for suspicious activity related to the drm/amdkfd component is also recommended. Asset inventory and rollback/change windows should be considered in remediation efforts. Source tracking and exposure reviews are crucial for ensuring comprehensive mitigation. The vulnerability's severity and potential impact necessitate immediate review and action by relevant stakeholders. Security teams should review the official advisory and CVE record to validate affected scope, severity, and vendor guidance. They should also plan vendor-supported updates or mitigations through normal change control where exposure is confirmed and review compensating controls for exposed systems while remediation is scheduled and verified. Exceptions should be tracked, and remediated assets should be retested before closing the item, with evidence documented accordingly. Monitoring, detection, and logs for exposed assets should be checked for extra review. The vulnerability requires a coordinated response from affected stakeholders to ensure timely mitigation and minimize potential risks. The CVE record and official advisory provide critical information for understanding and addressing the vulnerability effectively. By taking these steps, organizations can reduce the risk associated with this vulnerability and protect their systems from potential exploitation. The Linux kernel stable repository provides a patch for this vulnerability, which should be applied promptly to affected systems. In addition to

Technical summary

The kfd_criu_resume_svm function in the Linux kernel's drm/amdkfd component has a vulnerability that can lead to a double-free error. This occurs because the function walks the svms->criu_svm_metadata_list and kfree()s each struct criu_svm_metadata without removing it from the list, causing a use-after-free condition when the list is traversed again. The vulnerability is reachable by an unprivileged render-group user via /dev/kfd with no capabilities required.

Defensive priority

This vulnerability is reachable by an unprivileged render-group user via /dev/kfd with no capabilities required, indicating a need for prompt attention.

Recommended defensive actions

  • Apply the patch from the Linux kernel stable repository to fix the list_del corruption in kfd_criu_resume_svm.
  • Restrict access to /dev/kfd to only privileged users or those with specific capabilities.
  • Monitor for any suspicious activity related to the drm/amdkfd component.
  • Review the official advisory and CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE is based on a vulnerability in the Linux kernel's drm/amdkfd component, specifically in the kfd_criu_resume_svm function. The issue involves a list_del corruption that can lead to a double-free vulnerability. Evidence is limited to public sources and may not reflect the full scope or impact of the vulnerability. Defenders should verify affected systems and apply patches or mitigations as recommended by the vendor.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-72449 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-72449

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-72449 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72449

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/506e635aed05dbdeef11e3c59f6e42980cda5b6d

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/838b57b3e7ce8cce0fda56d0861add3d464dd6c8

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/8fa5655da368d0306c03e9dc9cda8ae2a7840926

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/96ac562a9ea3020981f536384711190841c81aa8

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/c8a8d350a273c005a48c64c4519d21b2a51c5ceb

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/e33a3bd5cb8d0cf1557dee014115f812c9686130

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.