7.8
CVE-2026-89808
- EPSS 0.16%
- Veröffentlicht 16.09.2026 10:30:41
- Zuletzt bearbeitet 17.09.2026 10:17:03
- Erkennungen
drm/amdkfd: Fix the case that vm range is hole at svm_migrate_copy_to_vram
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix the case that vm range is hole at svm_migrate_copy_to_vram When migration vm range is hole at cpu side(MIGRATE_PFN_MIGRATE set + MIGRATE_PFN_VALID unset) driver still allocates device pages. There is no dma map of src pages and migration. j is 0 and svm_migrate_copy_memory_gart() will return an uninitialized r. That can trigger out_free_vram_pages to drop all VRAM just set up. Initialize r and only call the last svm_migrate_copy_memory_gart if j > 0. Current code postponed the last page to the final copy. This patch flushes on the last page when reach to the end of current drm_buddy_block; avoids another svm_migrate_copy_memory_gart.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
50ea50cf6f6d31d3235ad1853c5dbea766a3ed11
Version <
ae806a95b28fcecb913430cfa45a252e91a945d6
Status
affected
Version
50ea50cf6f6d31d3235ad1853c5dbea766a3ed11
Version <
0a9a0e8a97da70a0336c9115178aaf1be29bcfb1
Status
affected
Version
50ea50cf6f6d31d3235ad1853c5dbea766a3ed11
Version <
520e345ffe05aabef1db82beda4288afb1757ff2
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
5.14
Status
affected
Version
0
Version <
5.14
Status
unaffected
Version <=
6.18.*
Version
6.18.51
Status
unaffected
Version <=
7.2.*
Version
7.2.5
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.058 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/ae806a95b28fcecb913430cfa45a252e91a945d6
https://git.kernel.org/stable/c/0a9a0e8a97da70a0336c9115178aaf1be29bcfb1
https://git.kernel.org/stable/c/520e345ffe05aabef1db82beda4288afb1757ff2