{"id":"CVE-2021-4460","title":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: Fix UBSAN shift-out-of-bounds warning\n\nIf get_num_sdma_queues or get_num_xgmi_sdma_queues is 0, we end up\ndoing a shift operation where the number of bits s…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: Fix UBSAN shift-out-of-bounds warning\n\nIf get_num_sdma_queues or get_num_xgmi_sdma_queues is 0, we end up\ndoing a shift operation where the number of bits s…","severity":"high","cvss":7.1,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","cwe":["CWE-125","CWE-125"],"vendor":"linux","product":"linux_kernel","affected":["linux_kernel < 5.4.118","linux_kernel >= 5.5, < 5.10.36","linux_kernel >= 5.11, < 5.11.20","linux_kernel >= 5.12, < 5.12.3"],"patched":["linux_kernel 5.12.3"],"published":"2025-10-01","updated":"2026-08-11","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2021-4460","references":[{"url":"https://git.kernel.org/stable/c/0c0356ef2498c1a250fe3846f30293f828737309","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1874b0ef1426b873de94c61861e38f29a8df714c","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3fdc5182700910a685d23df57d65166e8556a266","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/50e2fc36e72d4ad672032ebf646cecb48656efe0","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9069b1b542de8f3bbffef868aff41521b21485cf","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd"],"epss":0.00163,"epssPercentile":0.0481,"ingestedAt":"2026-08-11T16:47:03.762Z","slug":"CVE-2021-4460","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: Fix UBSAN shift-out-of-bounds warning\n\nIf get_num_sdma_queues or get_num_xgmi_sdma_queues is 0, we end up\ndoing a shift operation where the number of bits shifted equals\nnumber of bits in the operand. This behaviour is undefined.\n\nSet num_sdma_queues or num_xgmi_sdma_queues to ULLONG_MAX, if the\ncount is >= number of bits in the operand.\n\nBug: https://gitlab.freedesktop.org/drm/amd/-/issues/1472\n\n## Affected\n\n- `linux_kernel < 5.4.118`\n- `linux_kernel >= 5.5, < 5.10.36`\n- `linux_kernel >= 5.11, < 5.11.20`\n- `linux_kernel >= 5.12, < 5.12.3`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `linux_kernel 5.12.3`","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":39.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}