-
CVE-2026-89828
- EPSS 0.21%
- Veröffentlicht 16.09.2026 10:31:00
- Zuletzt bearbeitet 16.09.2026 11:16:49
- Erkennungen
drm/amdgpu: Fix init ordering in amdgpu_vram_mgr_init()
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix init ordering in amdgpu_vram_mgr_init() drmm_cgroup_register_region() is called before INIT_LIST_HEAD() and gpu_buddy_init() in amdgpu_vram_mgr_init(). If it fails, the function returns early and bypasses those initializations. Since adev->mman.initialized is set to true before amdgpu_vram_mgr_init() is called, a failure triggers amdgpu_ttm_fini(), which calls amdgpu_vram_mgr_fini(), which then: - Calls list_for_each_entry_safe() on reservations_pending and reserved_pages, whose list_head::next pointers are zero-initialized (NULL). The loop does not recognize them as empty and dereferences NULL. - Calls gpu_buddy_fini(), which iterates free_trees[] unconditionally via for_each_free_tree(). Since mm->free_trees is NULL (never allocated), this dereferences NULL. Both result in a kernel panic on the module load error path. Fix by moving drmm_cgroup_register_region() to after the list and buddy allocator are fully initialized, so the teardown path is safe to run.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
2b624a2c18656ea32e0849e7bc0018ba3c97ca64
Version <
e184e46ca1ba652ab8053a10a51b39aad06d3f5c
Status
affected
Version
2b624a2c18656ea32e0849e7bc0018ba3c97ca64
Version <
3e234c6face8651045f46895dfe9c086ea64f03b
Status
affected
Version
2b624a2c18656ea32e0849e7bc0018ba3c97ca64
Version <
e773798e14ac0aea54ca9676083b91f445e5bc59
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
6.14
Status
affected
Version
0
Version <
6.14
Status
unaffected
Version <=
6.18.*
Version
6.18.51
Status
unaffected
Version <=
7.2.*
Version
7.2.5
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.21% | 0.115 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/e184e46ca1ba652ab8053a10a51b39aad06d3f5c
https://git.kernel.org/stable/c/3e234c6face8651045f46895dfe9c086ea64f03b
https://git.kernel.org/stable/c/e773798e14ac0aea54ca9676083b91f445e5bc59