CVE-2026-89808

Summary

In the Linux kernel, the following vulnerability has been resolved:

drm/amdkfd: Fix the case that vm range is hole at svm_migrate_copy_to_vram

When migration vm range is hole at cpu side(MIGRATE_PFN_MIGRATE set + MIGRATE_PFN_VALID unset) driver still allocates device pages. There is no dma map of src pages and migration. j is 0 and svm_migrate_copy_memory_gart() will return an uninitialized r. That can trigger out_free_vram_pages to drop all VRAM just set up.

Initialize r and only call the last svm_migrate_copy_memory_gart if j > 0.

Current code postponed the last page to the final copy. This patch flushes on the last page when reach to the end of current drm_buddy_block; avoids another svm_migrate_copy_memory_gart.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < ae806a95b28fcecb913430cfa45a252e91a945d6affected
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 0a9a0e8a97da70a0336c9115178aaf1be29bcfb1affected
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 520e345ffe05aabef1db82beda4288afb1757ff2affected
LinuxLinux0 < 6.18.51affected
LinuxLinux0 < 7.2.5affected
LinuxLinux6.18.51 <= 6.18.*unaffected
LinuxLinux7.2.5 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References