Description
In the Linux kernel, the following vulnerability has been resolved:

drm/amdkfd: fix scope of mqd_mgr dereference in pqm_debugfs_mqds

Reading /sys/kernel/debug/kfd/mqds while a process holds an active KFD
queue triggers a NULL pointer dereference because the for loop that
calls mqd_mgr->debugfs_show_mqd() is incorrectly placed outside the
if (pqn->q) block that initializes mqd_mgr.

The queue list can contain entries where pqn->q is NULL (kernel queues
where only pqn->kq is valid). In the original code:

if (pqn->q) {
...
mqd_mgr = q->device->dqm->mqd_mgrs[mqd_type];
size = mqd_mgr->mqd_stride(...);
}

for (xcc = 0; xcc < num_xccs; xcc++) { // WRONG: outside if block
mqd = q->mqd + size * xcc;
r = mqd_mgr->debugfs_show_mqd(m, mqd);
}

When iterating over a queue node where pqn->q is NULL:
1. The if (pqn->q) block is skipped
2. mqd_mgr remains uninitialized (NULL from declaration)
3. The for loop executes anyway
4. mqd_mgr->debugfs_show_mqd(m, mqd) dereferences NULL

The crash manifests as:

BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor instruction fetch in kernel mode
RIP: 0010:0x0
Call Trace:
pqm_debugfs_mqds+0x10c/0x1d0 [amdgpu]
kfd_debugfs_mqds_by_process+0x9b/0x110 [amdgpu]
seq_read_iter+0x132/0x4b0
...

Fix by moving the for loop inside the if (pqn->q) block, so mqd_mgr
and related variables are only used when properly initialized.

(cherry picked from commit 8bfe29d5c798940f797aa24135d2734c3ffce9de)
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel Null Pointer Dereference (Denial of Service)
Action: Patch Kernel
AI Analysis

Impact

The vulnerability is a null pointer dereference in the AMD GPU KFD driver that occurs when a process reads /sys/kernel/debug/kfd/mqds while an active queue exists. Because the code mistakenly accesses mqd_mgr->debugfs_show_mqd() after the guard that initializes mqd_mgr, the pointer can be NULL. A kernel panic is triggered at that point, resulting in a denial of service on the affected system.

Affected Systems

All Linux kernel releases that include the AMD KFD driver and have not incorporated commit 8bfe29d5 (which moves the for‑loop inside the initialization guard) are vulnerable. The vulnerable code is part of the amdgpu module; hence any distribution using an unpatched amdgpu version before that commit is at risk. Exact version numbers are not provided, so any kernel from the time of the commit back to the module's release should be considered.

Risk and Exploitability

The EPSS score is indicated as less than 1 %, suggesting a very low likelihood of exploitation. The attack requires a local user who has read access to the kfd debugfs entries, permissions that are normally restricted to root or users with specific privileges. The vulnerability is not listed in the CISA KEV catalog. Therefore, while the potential impact is high (kernel crash), the probability of attack remains low under normal circumstances.

Generated by OpenCVE AI on September 18, 2026 at 11:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that includes the amdgpu commit moving the loop inside the guard, which removes the NPE.
  • If an immediate upgrade is not feasible, restrict access to the /sys/kernel/debug/kfd directory by remounting debugfs with mode 000 or by disabling the kfd debugfs entries through module options.
  • Monitor kernel logs (e.g., dmesg or /var/log/kern.log) for BUG: kernel NULL pointer dereference messages related to kfd and trigger an alert when they occur.

Generated by OpenCVE AI on September 18, 2026 at 11:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: fix scope of mqd_mgr dereference in pqm_debugfs_mqds Reading /sys/kernel/debug/kfd/mqds while a process holds an active KFD queue triggers a NULL pointer dereference because the for loop that calls mqd_mgr->debugfs_show_mqd() is incorrectly placed outside the if (pqn->q) block that initializes mqd_mgr. The queue list can contain entries where pqn->q is NULL (kernel queues where only pqn->kq is valid). In the original code: if (pqn->q) { ... mqd_mgr = q->device->dqm->mqd_mgrs[mqd_type]; size = mqd_mgr->mqd_stride(...); } for (xcc = 0; xcc < num_xccs; xcc++) { // WRONG: outside if block mqd = q->mqd + size * xcc; r = mqd_mgr->debugfs_show_mqd(m, mqd); } When iterating over a queue node where pqn->q is NULL: 1. The if (pqn->q) block is skipped 2. mqd_mgr remains uninitialized (NULL from declaration) 3. The for loop executes anyway 4. mqd_mgr->debugfs_show_mqd(m, mqd) dereferences NULL The crash manifests as: BUG: kernel NULL pointer dereference, address: 0000000000000000 #PF: supervisor instruction fetch in kernel mode RIP: 0010:0x0 Call Trace: pqm_debugfs_mqds+0x10c/0x1d0 [amdgpu] kfd_debugfs_mqds_by_process+0x9b/0x110 [amdgpu] seq_read_iter+0x132/0x4b0 ... Fix by moving the for loop inside the if (pqn->q) block, so mqd_mgr and related variables are only used when properly initialized. (cherry picked from commit 8bfe29d5c798940f797aa24135d2734c3ffce9de)
Title drm/amdkfd: fix scope of mqd_mgr dereference in pqm_debugfs_mqds
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T09:29:07.472Z

Reserved: 2026-09-11T19:38:34.767Z

Link: CVE-2026-89809

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:46.047

Modified: 2026-09-17T10:17:04.047

Link: CVE-2026-89809

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T11:15:07Z

Weaknesses