--- /dev/null
+From bb52249fbbe948875155ccd45cd8d74bf4ae747b Mon Sep 17 00:00:00 2001
+From: David Francis <David.Francis@amd.com>
+Date: Thu, 21 May 2026 09:18:59 -0400
+Subject: drm/amdkfd: Check bounds in allocate_event_notification_slot
+
+From: David Francis <David.Francis@amd.com>
+
+commit bb52249fbbe948875155ccd45cd8d74bf4ae747b upstream.
+
+The valid event ids go from 0 to KFD_SIGNAL_EVENT_LIMIT
+
+allocate_event_notification_slot has an option to specify
+an event id to allocate at, used by CRIU. We weren't checking
+the bounds on that value.
+
+Check them.
+
+v2: Lower bounds check is unecessary because of idr_alloc
+already rejecting negative numbers. Upper bounds check should
+be KFD_SIGNAL_EVENT_LIMIT since the signal mode mappings might
+not yet exist
+
+Signed-off-by: David Francis <David.Francis@amd.com>
+Reviewed-by: David Yat Sin <david.yatsin@amd.com>
+Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
+(cherry picked from commit 6853f1f6cbbeb3f53ebbbd7286536aeb2c5d5f50)
+Cc: stable@vger.kernel.org
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ drivers/gpu/drm/amd/amdkfd/kfd_events.c | 3 +++
+ 1 file changed, 3 insertions(+)
+
+--- a/drivers/gpu/drm/amd/amdkfd/kfd_events.c
++++ b/drivers/gpu/drm/amd/amdkfd/kfd_events.c
+@@ -106,6 +106,9 @@ static int allocate_event_notification_s
+ }
+
+ if (restore_id) {
++ if (*restore_id >= KFD_SIGNAL_EVENT_LIMIT)
++ return -EINVAL;
++
+ id = idr_alloc(&p->event_idr, ev, *restore_id, *restore_id + 1,
+ GFP_KERNEL);
+ } else {
drm-i915-gem-add-missing-nospec-on-parallel-submit-slot.patch
drm-nouveau-acr-fix-missing-nvkm_done-in-error-path-of-nvkm_acr_oneinit.patch
drm-radeon-fix-r100_copy_blit-for-large-bos.patch
+drm-amdkfd-check-bounds-in-allocate_event_notification_slot.patch
drm-displayid-fix-tiled-display-topology-id-size.patch