Description
In the Linux kernel, the following vulnerability has been resolved:

drm/amdkfd: guard against NULL restore_mqd in CRIU queue restore

Both create_queue_cpsch() and create_queue_nocpsch() unconditionally
call mqd_mgr->restore_mqd() when a CRIU restore is in progress
(qd != NULL), with no NULL guard. On any system where restore_mqd is
not implemented for the given queue type, a user holding
CAP_CHECKPOINT_RESTORE can trigger a kernel NULL pointer dereference
and panic the machine by issuing KFD_IOC_CRIU_OP_RESTORE with a
crafted queue restore object. Note that checkpoint_mqd is likewise
unimplemented on GFX12, so no legitimate CRIU image can reach this
path — only a hand-crafted restore payload.

Add a NULL guard for restore_mqd immediately after mqd_mgr is
resolved, unwinding via the existing error labels and returning
-EOPNOTSUPP if the callback is not implemented. This mirrors the
existing checkpoint_mqd guard in checkpoint_mqd().
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (Kernel Panic)
Action: Patch
AI Analysis

Impact

The vulnerability occurs when the drm/amdkfd module attempts to restore a CRIU queue without verifying that the restore callback is implemented. If restore_mqd is null and a restore is requested, the kernel performs a NULL pointer dereference that causes a panic, bringing the machine down. A user with CAP_CHECKPOINT_RESTORE can construct a malicious KFD_IOC_CRIU_OP_RESTORE request to trigger this path, resulting in a denial of service. The flaw is a NULL pointer dereference (CWE‑476).

Affected Systems

This flaw is in the Linux kernel drivers for the AMDKFD DRM subsystem, so it applies to all Linux kernel releases that contain this code path. The advisory does not list a specific version range, thus any kernel that has not yet incorporated the NULL guard is susceptible. All distributions shipping the unguarded code are also affected until a patch is applied.

Risk and Exploitability

The EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, indicating low public exploit probability. The required CAP_CHECKPOINT_RESTORE capability limits the attack to local users who already have privileged access, typically root or system services. The attack vector is a local privileged user sending a crafted restore payload; no information suggests that remote code execution is possible. The overall risk is a denial of service if the vulnerability is exploited on a privileged system.

Generated by OpenCVE AI on September 18, 2026 at 09:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that contains the NULL guard for restore_mqd in drm/amdkfd.
  • Revoke CAP_CHECKPOINT_RESTORE from non‑essential processes or users to limit the privilege required to trigger the crash.
  • If an immediate kernel upgrade is not possible, disable the use of KFD_IOC_CRIU_OP_RESTORE for unsupported queue types or apply an ad‑hoc patch that introduces a NULL check before calling restore_mqd.

Generated by OpenCVE AI on September 18, 2026 at 09:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: guard against NULL restore_mqd in CRIU queue restore Both create_queue_cpsch() and create_queue_nocpsch() unconditionally call mqd_mgr->restore_mqd() when a CRIU restore is in progress (qd != NULL), with no NULL guard. On any system where restore_mqd is not implemented for the given queue type, a user holding CAP_CHECKPOINT_RESTORE can trigger a kernel NULL pointer dereference and panic the machine by issuing KFD_IOC_CRIU_OP_RESTORE with a crafted queue restore object. Note that checkpoint_mqd is likewise unimplemented on GFX12, so no legitimate CRIU image can reach this path — only a hand-crafted restore payload. Add a NULL guard for restore_mqd immediately after mqd_mgr is resolved, unwinding via the existing error labels and returning -EOPNOTSUPP if the callback is not implemented. This mirrors the existing checkpoint_mqd guard in checkpoint_mqd().
Title drm/amdkfd: guard against NULL restore_mqd in CRIU queue restore
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:30:40.572Z

Reserved: 2026-09-11T19:38:34.767Z

Link: CVE-2026-89807

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:45.817

Modified: 2026-09-16T11:16:45.817

Link: CVE-2026-89807

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T09:30:06Z

Weaknesses