---
id: CVE-2021-4460
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  drm/amdkfd: Fix UBSAN shift-out-of-bounds warning

  If get_num_sdma_queues or get_num_xgmi_sdma_queues is 0, we end up
  doing a shift operation where the number of bits s…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  drm/amdkfd: Fix UBSAN shift-out-of-bounds warning

  If get_num_sdma_queues or get_num_xgmi_sdma_queues is 0, we end up
  doing a shift operation where the number of bits s…
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H'
cwe:
  - CWE-125
  - CWE-125
vendor: linux
product: linux_kernel
affected:
  - linux_kernel < 5.4.118
  - 'linux_kernel >= 5.5, < 5.10.36'
  - 'linux_kernel >= 5.11, < 5.11.20'
  - 'linux_kernel >= 5.12, < 5.12.3'
patched:
  - linux_kernel 5.12.3
published: '2025-10-01'
updated: '2026-08-11'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-4460'
references:
  - url: 'https://git.kernel.org/stable/c/0c0356ef2498c1a250fe3846f30293f828737309'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/1874b0ef1426b873de94c61861e38f29a8df714c'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/3fdc5182700910a685d23df57d65166e8556a266'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/50e2fc36e72d4ad672032ebf646cecb48656efe0'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/9069b1b542de8f3bbffef868aff41521b21485cf'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
epss: 0.00163
epssPercentile: 0.04839
ingestedAt: '2026-08-11T16:47:03.762Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

drm/amdkfd: Fix UBSAN shift-out-of-bounds warning

If get_num_sdma_queues or get_num_xgmi_sdma_queues is 0, we end up
doing a shift operation where the number of bits shifted equals
number of bits in the operand. This behaviour is undefined.

Set num_sdma_queues or num_xgmi_sdma_queues to ULLONG_MAX, if the
count is >= number of bits in the operand.

Bug: https://gitlab.freedesktop.org/drm/amd/-/issues/1472

## Affected

- `linux_kernel < 5.4.118`
- `linux_kernel >= 5.5, < 5.10.36`
- `linux_kernel >= 5.11, < 5.11.20`
- `linux_kernel >= 5.12, < 5.12.3`

## Remediation

Upgrade past the affected range:

- `linux_kernel 5.12.3`
