Description
In the Linux kernel, the following vulnerability has been resolved:

drm/radeon: fix memory leak in radeon_ring_restore() on lock failure

radeon_ring_restore() takes ownership of the data buffer allocated by
radeon_ring_backup(). The caller (radeon_gpu_reset()) only frees it in
the non-restore branch; in the restore branch it relies on
radeon_ring_restore() to free it.

If radeon_ring_lock() fails, the function returned early without calling
kvfree(data), leaking the ring backup buffer on every GPU reset that
fails at the lock stage. During repeated GPU resets this causes
cumulative kernel memory exhaustion.

Free data before returning the error.
Published: 2026-08-15
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exists in the DRM Radeon driver of the Linux kernel. The function radeon_ring_restore() frees a backup buffer only when the restore path succeeds. If a lock acquisition fails, the function exits early without freeing the buffer, resulting in a memory leak each time a GPU reset fails at the lock stage. Repeated lock failures can lead to cumulative kernel memory exhaustion, potentially destabilizing the system.

Affected Systems

All Linux kernel configurations that include the unpatched Radeon DRM driver may be affected. The specific kernel versions are not listed in the data, so any distribution shipping the driver code before the referenced commits is potentially impacted.

Risk and Exploitability

EPSS score of < 1% indicates a very low probability of active exploitation, while the CVSS score of 5.5 reflects a moderate severity due to the memory exhaustion potential. The vulnerability is not listed in the CISA KEV catalog. The issue can be triggered by repeated GPU resets that hit the lock failure path in radeon_ring_restore(); an attacker that can induce such resets—whether locally or remotely—may cause cumulative kernel memory exhaustion, leading to a denial‑of‑service condition on the affected host.

Generated by OpenCVE AI on August 22, 2026 at 00:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the kernel to a version that contains the commits referenced in the advisory (e.g., commit 06dc892561f5...).
  • If an upgrade is not immediately possible, reboot the system to clear the leaked memory and avoid triggering continuous GPU resets.
  • Monitor kernel logs for GPU reset errors and consider disabling automatic GPU resets if the hardware and driver permit, to limit the accumulation of leaked buffers.

Generated by OpenCVE AI on August 22, 2026 at 00:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-404

Thu, 20 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-772
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Low


Sat, 15 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-404

Sat, 15 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm/radeon: fix memory leak in radeon_ring_restore() on lock failure radeon_ring_restore() takes ownership of the data buffer allocated by radeon_ring_backup(). The caller (radeon_gpu_reset()) only frees it in the non-restore branch; in the restore branch it relies on radeon_ring_restore() to free it. If radeon_ring_lock() fails, the function returned early without calling kvfree(data), leaking the ring backup buffer on every GPU reset that fails at the lock stage. During repeated GPU resets this causes cumulative kernel memory exhaustion. Free data before returning the error.
Title drm/radeon: fix memory leak in radeon_ring_restore() on lock failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-17T05:18:58.660Z

Reserved: 2026-08-15T05:44:03.893Z

Link: CVE-2026-74416

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:22:43.690

Modified: 2026-08-17T06:19:37.063

Link: CVE-2026-74416

cve-icon Redhat

Severity : Low

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-74416 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T00:30:16Z

Weaknesses
  • CWE-772

    Missing Release of Resource after Effective Lifetime