{"id":"CVE-2026-97422","published":"2026-09-24T17:17:20.113","lastModified":"2026-09-25T13:17:25.773","description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: fix SMI event cross-process information leak\n\nkfd_smi_ev_enabled() skips the suser privilege check when pid=0.\nPROCESS_START, PROCESS_END, and VMFAULT events are emitted with\npid=0 while carrying another process's PID and command name, so any\n/dev/kfd user in the render group can monitor all GPU workloads.\n\nPass the target process PID into kfd_smi_event_add() for these events\nso the existing per-client filter restricts delivery to the owning\nprocess or CAP_SYS_ADMIN subscribers.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/5bb2dfa65d8da83e87b2a31c270bc567df69a5ca","tags":[]},{"url":"https://git.kernel.org/stable/c/92a8dba246d371fe268280e5fd74b0955688e6df","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}