CVE-2026-98178

Summary

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu: Skip KFD mapping clear before initialization

amdgpu_amdkfd_clear_kfd_mapping() assumes that a non-NULL kfd_dev has a fully populated node array. This is not true when KFD device initialization fails after probe.

For example, kgd2kfd_device_init() sets num_nodes before checking PCIe atomics support. On Polaris systems without the required atomics, it returns before allocating nodes[0], but the kfd_dev remains attached to the amdgpu device. A later GPU reset then dereferences nodes[0]->id.

Require the authoritative KFD initialization flag before walking the node array, matching the existing KFD reset and teardown paths.

(cherry picked from commit 4ac1835823c47903fbb278bbf474773c46f59edc)

Affected Software

VendorProductVersion RangeStatus
LinuxLinux70cadefcc6160c575b04f763ada34c20e868d577 < 157d3f1db7e7e6f320daa221fae84a4c13555b6faffected
LinuxLinux70cadefcc6160c575b04f763ada34c20e868d577 < 7f9caa70aef0950e06d395ca0035831214d88187affected
LinuxLinux7.2affected
LinuxLinux0 < 7.2unaffected
LinuxLinux7.2.8 <= 7.2.*unaffected
LinuxLinux7.3-rc4 <= *unaffected

Weaknesses

References