CVE-2026-89814

Summary

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu: clamp the isolation index for rings outside a partition

adev->isolation[] has one slot per partition, but a ring that is not assigned to one keeps AMDGPU_XCP_NO_PARTITION, which is ~0, so indexing the array with it is out of bounds. SDMA submissions hit this on both the isolation enforcement and the VM flush path and trip UBSAN.

Fall back to the first slot the way the cleaner shader path already does, and stop taking the address before the ring type check that makes it relevant.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 964de255497ffd7cb8a86e405b8ac6d927e7e177affected
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 0bfb938182d1313e5cac32ae38dbaaa4eabe4af4affected
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < b30900566642ceb2c9e12b56c2afec28d0fd91a0affected
LinuxLinux0 < 6.18.51affected
LinuxLinux0 < 7.2.5affected
LinuxLinux6.18.51 <= 6.18.*unaffected
LinuxLinux7.2.5 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References