CVE-2026-98178 PUBLISHED

drm/amdgpu: Skip KFD mapping clear before initialization

Assigner: Linux
Reserved: 25.09.2026 Published: 06.10.2026 Updated: 06.10.2026

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu: Skip KFD mapping clear before initialization

amdgpu_amdkfd_clear_kfd_mapping() assumes that a non-NULL kfd_dev has a fully populated node array. This is not true when KFD device initialization fails after probe.

For example, kgd2kfd_device_init() sets num_nodes before checking PCIe atomics support. On Polaris systems without the required atomics, it returns before allocating nodes[0], but the kfd_dev remains attached to the amdgpu device. A later GPU reset then dereferences nodes[0]->id.

Require the authoritative KFD initialization flag before walking the node array, matching the existing KFD reset and teardown paths.

(cherry picked from commit 4ac1835823c47903fbb278bbf474773c46f59edc)

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 70cadefcc6160c575b04f763ada34c20e868d577 to 157d3f1db7e7e6f320daa221fae84a4c13555b6f (excl.)
  • affected from 70cadefcc6160c575b04f763ada34c20e868d577 to 7f9caa70aef0950e06d395ca0035831214d88187 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 7.2 is affected
  • unaffected from 0 to 7.2 (excl.)
  • unaffected from 7.2.8 to 7.2.* (incl.)
  • unaffected from 7.3-rc4 to * (incl.)

References