{"id":"CVE-2026-97422","title":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: fix SMI event cross-process information leak\n\nkfd_smi_ev_enabled() skips the suser privilege check when pid=0.\nPROCESS_START, PROCESS_END, and VMFAULT event…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: fix SMI event cross-process information leak\n\nkfd_smi_ev_enabled() skips the suser privilege check when pid=0.\nPROCESS_START, PROCESS_END, and VMFAULT event…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 5bb2dfa65d8da83e87b2a31c270bc567df69a5ca","Linux >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 92a8dba246d371fe268280e5fd74b0955688e6df","Linux < 6.18.53","Linux (all versions)"],"published":"2026-09-24","updated":"2026-09-24","sourceUpdated":"2026-09-24T17:17:20.113","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-97422","references":[{"url":"https://git.kernel.org/stable/c/5bb2dfa65d8da83e87b2a31c270bc567df69a5ca","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/92a8dba246d371fe268280e5fd74b0955688e6df","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-24T16:47:15.883Z","slug":"CVE-2026-97422","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: fix SMI event cross-process information leak\n\nkfd_smi_ev_enabled() skips the suser privilege check when pid=0.\nPROCESS_START, PROCESS_END, and VMFAULT events are emitted with\npid=0 while carrying another process's PID and command name, so any\n/dev/kfd user in the render group can monitor all GPU workloads.\n\nPass the target process PID into kfd_smi_event_add() for these events\nso the existing per-client filter restricts delivery to the owning\nprocess or CAP_SYS_ADMIN subscribers.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}