{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.85-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.18.14-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  drm/amdkfd: Fix watch_id bounds checking in debug address watch v2  The address watch clear code receives watch_id as an unsigned value (u32), but some helper functions were using a signed int and checked bits by shifting with watch_id.  If a very large watch_id is passed from userspace, it can be converted to a negative value.  This can cause invalid shifts and may access memory outside the watch_points array.  drm/amdkfd: Fix watch_id bounds checking in debug address watch v2  Fix this by checking that watch_id is within MAX_WATCH_ADDRESSES before using it.  Also use BIT(watch_id) to test and clear bits safely.  This keeps the behavior unchanged for valid watch IDs and avoids undefined behavior for invalid ones.  Fixes the below: drivers/gpu/drm/amd/amdgpu/../amdkfd/kfd_debug.c:448 kfd_dbg_trap_clear_dev_address_watch() error: buffer overflow 'pdd-\u003ewatch_points' 4 \u003c= u32max user_rl='0-3,2147483648-u32max' uncapped  drivers/gpu/drm/amd/amdgpu/../amdkfd/kfd_debug.c     433 int kfd_dbg_trap_clear_dev_address_watch(struct kfd_process_device *pdd,     434                                         uint32_t watch_id)     435 {     436         int r;     437     438         if (!kfd_dbg_owns_dev_watch_id(pdd, watch_id))  kfd_dbg_owns_dev_watch_id() doesn't check for negative values so if watch_id is larger than INT_MAX it leads to a buffer overflow. (Negative shifts are undefined).      439                 return -EINVAL;     440     441         if (!pdd-\u003edev-\u003ekfd-\u003eshared_resources.enable_mes) {     442                 r = debug_lock_and_unmap(pdd-\u003edev-\u003edqm);     443                 if (r)     444                         return r;     445         }     446     447         amdgpu_gfx_off_ctrl(pdd-\u003edev-\u003eadev, false); --\u003e 448         pdd-\u003ewatch_points[watch_id] = pdd-\u003edev-\u003ekfd2kgd-\u003eclear_address_watch(     449                                                         pdd-\u003edev-\u003eadev,     450                                                         watch_id);  v2: (as per, Jonathan Kim)  - Add early watch_id \u003e= MAX_WATCH_ADDRESSES validation in the set path to    match the clear path.  - Drop the redundant bounds check in kfd_dbg_owns_dev_watch_id().",
  "id": "DEBIAN-CVE-2026-45878",
  "modified": "2026-09-14T16:47:41.892057301Z",
  "published": "2026-05-27T14:17:01.547Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-45878"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-45878"
  ]
}