CVE-2026-98270 PUBLISHED

drm/amdgpu: check ras and obj before dereference

Assigner: Linux
Reserved: 25.09.2026 Published: 06.10.2026 Updated: 06.10.2026

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu: check ras and obj before dereference

nbio_v7_9_handle_ras_controller_intr_no_bifring() dereferences ras and obj without checking either for NULL. Both amdgpu_ras_get_context() and amdgpu_ras_find_obj() can return NULL, e.g. during the window between adev->nbio.ras being set (early in amdgpu_ras_init(), by design, to enable the fatal-error interrupt as soon as possible) and the PCIE_BIF ras object actually being created in RAS late_init. Any interrupt in that window crashes in hard-IRQ context.

This is analogous to commit d190b459b2a4 ("drm/amdgpu: the warning dereferencing obj for nbio_v7_4"), which fixed the same issue in the nbio_v7_4 handler.

Found by Linux Verification Center (linuxtesting.org) with SVACE.

(cherry picked from commit c7071767a50a32ed727cf800ac84372429e3b4b3)

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 7692e1ee2446fd1940b5caa6e09779504a58881a to b7c7f07a40037514f8e890aa00f8d7b196d680cf (excl.)
  • affected from 7692e1ee2446fd1940b5caa6e09779504a58881a to fc5f845a291fc8175e6857cd6ad042818da192e8 (excl.)
  • affected from 7692e1ee2446fd1940b5caa6e09779504a58881a to 37583946d8751f8e285c467d770ac0b609b82a23 (excl.)
  • affected from 7692e1ee2446fd1940b5caa6e09779504a58881a to 315c22712715491f0dfafdaf2c2b437540e68702 (excl.)
  • affected from 7692e1ee2446fd1940b5caa6e09779504a58881a to 723d4dc628d764b19cf9efca14b82cca5ff020c9 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.6 is affected
  • unaffected from 0 to 6.6 (excl.)
  • unaffected from 6.6.158 to 6.6.* (incl.)
  • unaffected from 6.12.112 to 6.12.* (incl.)
  • unaffected from 6.18.54 to 6.18.* (incl.)
  • unaffected from 7.2.8 to 7.2.* (incl.)
  • unaffected from 7.3-rc4 to * (incl.)

References