CVE-2026-98178
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: Skip KFD mapping clear before initialization
amdgpu_amdkfd_clear_kfd_mapping() assumes that a non-NULL kfd_dev has a fully populated node array. This is not true when KFD device initialization fails after probe.
For example, kgd2kfd_device_init() sets num_nodes before checking PCIe atomics support. On Polaris systems without the required atomics, it returns before allocating nodes[0], but the kfd_dev remains attached to the amdgpu device. A later GPU reset then dereferences nodes[0]->id.
Require the authoritative KFD initialization flag before walking the node array, matching the existing KFD reset and teardown paths.
(cherry picked from commit 4ac1835823c47903fbb278bbf474773c46f59edc)
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 70cadefcc6160c575b04f763ada34c20e868d577 < 157d3f1db7e7e6f320daa221fae84a4c13555b6f | affected |
| Linux | Linux | 70cadefcc6160c575b04f763ada34c20e868d577 < 7f9caa70aef0950e06d395ca0035831214d88187 | affected |
| Linux | Linux | 7.2 | affected |
| Linux | Linux | 0 < 7.2 | unaffected |
| Linux | Linux | 7.2.8 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc4 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/157d3f1db7e7e6f320daa221fae84a4c13555b6f
- https://git.kernel.org/stable/c/7f9caa70aef0950e06d395ca0035831214d88187
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.