Description
In the Linux kernel, the following vulnerability has been resolved:

drm/amdkfd: Fix the case that vm range is hole at svm_migrate_copy_to_vram

When migration vm range is hole at cpu side(MIGRATE_PFN_MIGRATE set +
MIGRATE_PFN_VALID unset) driver still allocates device pages. There is no
dma map of src pages and migration. j is 0 and svm_migrate_copy_memory_gart()
will return an uninitialized r. That can trigger out_free_vram_pages to drop
all VRAM just set up.

Initialize r and only call the last svm_migrate_copy_memory_gart if j > 0.

Current code postponed the last page to the final copy. This patch flushes on
the last page when reach to the end of current drm_buddy_block; avoids another
svm_migrate_copy_memory_gart.
Published: 2026-09-16
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via VRAM deallocation in AMD KFD
Action: Patch update
AI Analysis

Impact

The vulnerability occurs in the Linux kernel's AMD KFD driver when a VM range contains a hole on the CPU side; the driver allocates device pages without a proper DMA map and uses an uninitialized variable in the migration copy routine. This leads to a call that can drop all VRAM previously allocated, effectively destroying graphics memory resources. The flaw can therefore result in a denial‑of‑service condition for any process relying on the kernel’s graphics memory allocation. The weakness is rooted in the use of an uninitialized variable.

Affected Systems

It affects Linux kernel releases that include the drm/amdkfd module before the patch identified by commit 0a9a0e8a97da70a0336c9115178aaf1be29bcfb1. The specific kernel versions are not enumerated in the advisory, but all kernels with AMD KFD DRM support prior to the fix are potentially affected.

Risk and Exploitability

The CVSS score of 7.8 classifies the issue as high severity. The EPSS score of less than 1% indicates that exploitation probability is currently very low. The vulnerability is not listed in CISA’s KEV catalog, suggesting no known public exploitation. The attack vector would likely require privileged kernel context or the ability to trigger a migration of a VM range with a hole; an attacker could induce the problematic scenario either through a crafted application that uses KFD or by leveraging an existing privileged process. If successfully exploited, the vulnerability could lead to drastic loss of VRAM and instability of GPU‑dependent workloads.

Generated by OpenCVE AI on September 18, 2026 at 09:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to a Linux kernel release that contains the patches noted in commit 0a9a0e8a97da70a0336c9115178aaf1be29bcfb1.
  • If immediate kernel upgrade is not possible, consider unloading or disabling the amdkfd module to eliminate the risk of triggering the faulty migration path.
  • Monitor kernel logs (dmesg) for out_free_vram_pages or related errors indicating unexpected VRAM deallocation and verify that no further corruption occurs.

Generated by OpenCVE AI on September 18, 2026 at 09:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-457

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix the case that vm range is hole at svm_migrate_copy_to_vram When migration vm range is hole at cpu side(MIGRATE_PFN_MIGRATE set + MIGRATE_PFN_VALID unset) driver still allocates device pages. There is no dma map of src pages and migration. j is 0 and svm_migrate_copy_memory_gart() will return an uninitialized r. That can trigger out_free_vram_pages to drop all VRAM just set up. Initialize r and only call the last svm_migrate_copy_memory_gart if j > 0. Current code postponed the last page to the final copy. This patch flushes on the last page when reach to the end of current drm_buddy_block; avoids another svm_migrate_copy_memory_gart.
Title drm/amdkfd: Fix the case that vm range is hole at svm_migrate_copy_to_vram
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T09:29:06.263Z

Reserved: 2026-09-11T19:38:34.767Z

Link: CVE-2026-89808

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:45.940

Modified: 2026-09-17T10:17:03.883

Link: CVE-2026-89808

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T10:00:06Z

Weaknesses
  • CWE-457

    Use of Uninitialized Variable