CVE-2026-68259

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Check bounds in allocate_event_notification_slot The valid event ids go from 0 to KFD_SIGNAL_EVENT_LIMIT allocate_event_notification_slot has an option to specify an event id to allocate at, used by CRIU. We weren't checking the bounds on that value. Check them. v2: Lower bounds check is unecessary because of idr_alloc already rejecting negative numbers. Upper bounds check should be KFD_SIGNAL_EVENT_LIMIT since the signal mode mappings might not yet exist (cherry picked from commit 6853f1f6cbbeb3f53ebbbd7286536aeb2c5d5f50)

Package Linux Kernel
Published 2026-08-10
Last modified 2026-08-19
Patch available
Yes

Affected versions

Linux kernel versions 5.18 and later are affected. Fixed in 6.1.183, 6.6.148, 6.12.101, 6.18.42, 7.1.6, 7.2 and their respective stable series.

Affected from
≥ 5.18
Fixed in
✓ 6.1.183 6.1.x ✓ 6.6.148 6.6.x ✓ 6.12.101 6.12.x ✓ 6.18.42 6.18.x ✓ 7.1.6 7.1.x ✓ 7.2

Frequently asked questions

  • What is CVE-2026-68259?

    CVE-2026-68259 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 5.18 onward and has been patched in 6.1.183, 6.6.148, 6.12.101 and others. CVE-2026-68259 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.

  • Is there a patch available for CVE-2026-68259?

    Yes. CVE-2026-68259 has been patched. Fixed versions include 6.1.183, 6.6.148, 6.12.101 and others. If you are running Linux kernel 5.18 or later up to the fix versions, apply the relevant patch for your kernel branch.

  • Is CVE-2026-68259 actively exploited?

    No. CVE-2026-68259 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.