PatchSiren cyber security CVE debrief
CVE-2026-97496 Linux CVE debrief
The Linux kernel vulnerability CVE-2026-97496 is a high-severity issue in the drm/amdkfd component. An attacker can exploit this vulnerability to leak adjacent kernel memory, potentially exposing sensitive information. The vulnerability has been resolved through a fix that clamps cp_hqd_cntl_stack_size and cp_hqd_cntl_stack_offset values to prevent an unbounded copy_to_user() operation.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-24
- Original CVE updated
- 2026-09-25
- Advisory published
- 2026-09-24
- Advisory updated
- 2026-09-25
Who should care
Linux kernel developers and administrators should assess exposure and prioritize patching to prevent potential exploitation. They should review the official advisory and assess their system's exposure. Additionally, they should implement additional security measures to protect against potential attacks and monitor system logs for potential exploitation attempts.
Why it matters
CVE-2026-97496 is a high-severity Linux kernel vulnerability that can be exploited to leak adjacent kernel memory, potentially exposing sensitive information. Linux kernel developers and administrators should assess exposure and prioritize patching to prevent potential exploitation.
- Potential exposure of sensitive kernel memory
- Possible leak of adjacent kernel memory
- Need for patching to prevent exploitation
Technical summary
The get_wave_state() function in the Linux kernel's drm/amdkfd component trusts cp_hqd_cntl_stack_size and cp_hqd_cntl_stack_offset values read directly from the MQD, which are written by GPU microcode and fully attacker-controlled on the CRIU-restore path. This leads to an unbounded copy_to_user() operation that can leak adjacent GTT/kernel memory. The fix clamps cp_hqd_cntl_stack_size to the actual allocated buffer size (q->ctl_stack_size) and cp_hqd_cntl_stack_offset to the clamped size before performing arithmetic and copy_to_user(). This ensures that the kernel does not read beyond the allocated kernel BO regardless of attacker-supplied MQD field values. The vulnerability has a high CVSS score of 7.1 and a
Defensive priority
High
Recommended defensive actions
- Review and apply the Linux kernel patch to fix the vulnerability
- Monitor system logs for potential exploitation attempts
- Implement additional security measures to protect against potential attacks
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD vulnerability detail page provide information on the vulnerability, including its description, CVSS score, and affected products. The Linux kernel patch notes also provide details on the fix. However, the patch notes do not provide explicit evidence of the vulnerability's impact on specific systems or networks. To verify the vulnerability, defenders should review the official advisory and assess their system's exposure. The vulnerability has been resolved through a fix that clamps cp_hqd_cntl_stack_size and cp_h
Sources and references
Verified primary and authoritative sources
-
CVE-2026-97496 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-97496
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-97496 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-97496
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/7ef144458f48d5589e36f1b3d83e83db2e5c5ba5
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/d9183d974ddd5f09d029beaf359275ac20d4d5fe
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/ec646686613d8ab05b282d1463a7baa49fd6b83b
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.