PatchSiren cyber security CVE debrief
CVE-2026-74448 Linux CVE debrief
A use-after-free vulnerability was discovered in the Linux kernel's drm/amdkfd component. The vulnerability occurs when MES is enabled and amdgpu_amdkfd_alloc_kernel_mem() fails during the first queue creation for a process. This leads to a QID bit leak in pqm_create_queue(), potentially exhausting all available queue slots over time. The affected product is the Linux kernel, specifically the drm/amdkfd component. The vulnerability class is a use-after-free issue, and the likely operational impact is queue slot exhaustion. The source confidence is high, but review context is limited to the provided source corpus.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-15
- Original CVE updated
- 2026-08-15
- Advisory published
- 2026-08-15
- Advisory updated
- 2026-08-15
Who should care
Linux kernel developers and maintainers, users of Linux distributions with the affected kernel versions, and security teams responsible for patch management and vulnerability mitigation.
Technical summary
The vulnerability occurs in pqm_create_queue() when MES is enabled and amdgpu_amdkfd_alloc_kernel_mem() fails during the first queue creation for a process. The fix involves replacing 'return retval' with 'goto err_allocate_pqn' to ensure proper cleanup and prevent QID bit leaks. This issue affects the Linux kernel's drm/amdkfd component, potentially leading to queue slot exhaustion over time. The defensive impact is medium, and the source-grounded technical framing indicates a high severity issue.
Defensive priority
Medium
Recommended defensive actions
- Review and apply the provided patch to the Linux kernel's drm/amdkfd component
- Monitor Linux kernel updates for additional fixes related to drm/amdkfd
- Consider implementing compensating controls to detect and prevent potential exploitation
- Perform thorough testing of the patched kernel version
- Review system logs for signs of potential exploitation
- Inventory affected systems and prioritize patching based on risk
- Track patch deployment and verify successful implementation
Evidence notes
The vulnerability was resolved by replacing 'return retval' with 'goto err_allocate_pqn' in pqm_create_queue() to ensure clear_bit() is always called on the error path. This fix prevents QID bit leaks, potentially exhausting all available queue slots over time. Linux kernel developers should verify the patch implementation and test it thoroughly. The fix was introduced in a specific commit (a107f74c38edbb80d6ab64dcaeeb292c14e9779f) and backported to relevant kernel versions. Further review of the drm/amdkfd component may be necessary to identify similar issues.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-74448 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-74448
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-74448 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-74448
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/2ff5bb3645c72b3690e70c513a62a86600c4632f
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/38b73293f38658a4685ffcea666462024f858ad9
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/5f0f2ddeac738e2ca9d12cb76a1ff2904e85ecc3
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/7c35bf94150d872e670a6632aa819d320279effb
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/8924e2594a15bdbd07f8696770864366d787ab70
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.