CVE-2026-97422EPSS p4.1%
CVE-2026-97422CVE-2026-97422
Description
In the Linux kernel, the following vulnerability has been resolved:
drm/amdkfd: fix SMI event cross-process information leak
kfd_smi_ev_enabled() skips the suser privilege check when pid=0.
PROCESS_START, PROCESS_END, and VMFAULT events are emitted with
pid=0 while carrying another process's PID and command name, so any
/dev/kfd user in the render group can monitor all GPU workloads.
Pass the target process PID into kfd_smi_event_add() for these events
so the existing per-client filter restricts delivery to the owning
process or CAP_SYS_ADMIN subscribers.
Scoring
| EPSS | 0.15% probability of exploitation · percentile 4.1% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-25 |