CVE-2026-80608

Summary

In the Linux kernel, the following vulnerability has been resolved:

accel/amdxdna: Fix iommu domain lifetime race during device removal

When force_iova mode is enabled, amdxdna_remove() frees xdna->domain. If amdxdna_gem_obj_free() is called after device removal, it may attempt to access xdna->domain, resulting in a use-after-free.

Fix the race by adding freeing xdna->domain as a managed release action, so its lifetime is managed by DRM and remains valid until all managed resources are released.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxece3e8980907818c72dc9faa7bbaf40488ef1824 < 65e7e2b8d71b418439ebc68e80ed3e5a325375d6affected
LinuxLinuxece3e8980907818c72dc9faa7bbaf40488ef1824 < b4a0500fdf6e61a6c5f92ff2e61bc91578075803affected
LinuxLinux7.1affected
LinuxLinux0 < 7.1unaffected
LinuxLinux7.1.5 <= 7.1.*unaffected
LinuxLinux7.2 <= *unaffected

Weaknesses

References