In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: clamp v9 CRIU control stack checkpoint copy to BO size CRIU… (CVE-2026-68447)
A vulnerability in the Linux kernel's drm/amdkfd component allowed CRIU checkpoint copies to read past the allocated buffer object (BO) size into adjacent graphics translation table (GTT) memory. This could lead to leakage of kernel data to userspace. The issue was fixed by clamping the checkpoint copy size to the allocated BO size, preventing out-of-bounds reads.
AI Analysis
Technical Summary
The Linux kernel vulnerability CVE-2026-68447 involves the drm/amdkfd driver where CRIU checkpointing copies the MQD control stack using a hardware-reported size without bounding it to the allocated buffer object (BO) size. If the hardware-reported size exceeds the allocated control stack size, memcpy reads beyond the BO into adjacent GTT memory, potentially leaking kernel data to userspace. The fix stores the page-aligned control stack BO size and clamps checkpoint copy sizes to the minimum of the hardware-reported size and the allocated size, including adjustments for multi-XCC v9.4.3 checkpoint layouts.
Potential Impact
This vulnerability can lead to unintended disclosure of kernel memory contents to userspace processes, potentially exposing sensitive kernel data. There is no indication of code execution or privilege escalation. No known exploits in the wild have been reported.
Mitigation Recommendations
A fix has been applied in the Linux kernel to clamp the checkpoint copy size to the allocated BO size, preventing out-of-bounds reads. Users should update to a kernel version that includes this fix. Patch status is not explicitly confirmed in the provided data; therefore, check the vendor advisory or Linux kernel mailing lists for the exact fixed version and apply the update accordingly.
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: clamp v9 CRIU control stack checkpoint copy to BO size CRIU… (CVE-2026-68447)
Description
A vulnerability in the Linux kernel's drm/amdkfd component allowed CRIU checkpoint copies to read past the allocated buffer object (BO) size into adjacent graphics translation table (GTT) memory. This could lead to leakage of kernel data to userspace. The issue was fixed by clamping the checkpoint copy size to the allocated BO size, preventing out-of-bounds reads.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel vulnerability CVE-2026-68447 involves the drm/amdkfd driver where CRIU checkpointing copies the MQD control stack using a hardware-reported size without bounding it to the allocated buffer object (BO) size. If the hardware-reported size exceeds the allocated control stack size, memcpy reads beyond the BO into adjacent GTT memory, potentially leaking kernel data to userspace. The fix stores the page-aligned control stack BO size and clamps checkpoint copy sizes to the minimum of the hardware-reported size and the allocated size, including adjustments for multi-XCC v9.4.3 checkpoint layouts.
Potential Impact
This vulnerability can lead to unintended disclosure of kernel memory contents to userspace processes, potentially exposing sensitive kernel data. There is no indication of code execution or privilege escalation. No known exploits in the wild have been reported.
Mitigation Recommendations
A fix has been applied in the Linux kernel to clamp the checkpoint copy size to the allocated BO size, preventing out-of-bounds reads. Users should update to a kernel version that includes this fix. Patch status is not explicitly confirmed in the provided data; therefore, check the vendor advisory or Linux kernel mailing lists for the exact fixed version and apply the update accordingly.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-m433-x9mx-qcj6
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-68447"]
- Ecosystems
- []
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a7c9b67bf8831d539cdf2f8
Added to database: 08/12/2026, 16:12:23 UTC
Last enriched: 08/12/2026, 17:14:30 UTC
Last updated: 08/13/2026, 00:41:14 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.