In the Linux kernel, the following vulnerability has been resolved:
drm/amdkfd: Fix UBSAN shift-out-of-bounds warning
If get_num_sdma_queues or get_num_xgmi_sdma_queues is 0, we end up doing a shift operation where the number of bits shifted equals number of bits in the operand. This behaviour is undefined.
Set num_sdma_queues or num_xgmi_sdma_queues to ULLONG_MAX, if the count is >= number of bits in the operand.
Bug: https://gitlab.freedesktop.org/drm/amd/-/issues/1472
| Software | From | Fixed in |
|---|---|---|
| linux / linux_kernel | - | 5.4.118 |
| linux / linux_kernel | 5.5 | 5.10.36 |
| linux / linux_kernel | 5.11 | 5.11.20 |
| linux / linux_kernel | 5.12 | 5.12.3 |