CVE-2026-98177

Source
https://cve.org/CVERecord?id=CVE-2026-98177
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98177.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98177
Downstream
Published
2026-10-06T08:44:20Z
Modified
2026-10-08T02:52:50Z
Summary
drm/amdkfd: Avoid integer underflow in EOP ring size calculation.
Details

In the Linux kernel, the following vulnerability has been resolved:

drm/amdkfd: Avoid integer underflow in EOP ring size calculation.

The low 6 bits of cp_hqd_eop_control store the base-2 logarithm of the EOP ring size. This was calculated as

order_base_2(q->eop_ring_buffer_size / 4) - 1

But order_base_2 can in theory return 0, so this could underflow (although in practice the ring buffer size cannot be less than 4096).

Change this to

order_base_2(q->eop_ring_buffer_size / 8)

using properties of logarithms.

Also add to the above comment to make the mathematics more clear.

(cherry picked from commit f0f43fcf8b2b3a924cad9444340921c96ed5f634)

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98177.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
d696d536f0a97ac779d6176107ac4e96d0a2f8b9
Fixed
287a34c4d712e0bdb67751e21316d9c8d75a528a
Fixed
8ee521b8b189799e361d4233c5180ba56656d4d4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98177.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.3.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98177.json"