Description
In the Linux kernel, the following vulnerability has been resolved:

drm/amdkfd: Fix error path at svm_migrate_copy_to_ram

If page migration from device to sys ram fails for some reasons driver needs
release and unlock allocated system pages. To do that driver should use page
physical address, or pfn, then get struct page*. Current driver uses dma
address(for adev) that is not correct with IOMMU enabled, or even in general.

The patch releases and unlocks allocated system pages based on where migration
failed by struct page* of sys ram pages. Also dma_unmap correspodent system
ram pages at error path.
Published: 2026-09-16
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption
Action: Immediate patch
AI Analysis

Impact

In the Linux kernel, the amdkfd DRM driver incorrectly releases and unmaps system pages when migration from an AMD device’s GPU memory to system RAM fails. The driver uses the DMA address associated with the device instead of the physical frame number of the system page, causing the kernel to free or map incorrect memory. This error path can corrupt kernel memory that remains in use, leading to kernel crashes, data corruption, or the potential for arbitrary code execution. The flaw is a classic use‑after‑free or improper memory deallocation issue.

Affected Systems

All Linux kernel variants that include the AMD Kernel Framebuffer (amdkfd) DRM component are affected. Without a specific version list from the vendor, the issue potentially exists in any kernel release before the patch sequence referenced in the advisory. The vulnerability primarily impacts systems running AMD GPUs with the amdkfd driver enabled, regardless of distribution.

Risk and Exploitability

The CVSS score of 7.8 indicates a high‑severity vulnerability, but the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The flaw is not listed in the CISA KEV catalog. Exploitation would require local access, privilege escalation, or a vulnerability that triggers the defective migration path, and the attacker would need an IOMMU‑enabled environment to expose the bug. If successfully leveraged, the kernel memory corruption could lead to arbitrary code execution or system instability.

Generated by OpenCVE AI on September 18, 2026 at 09:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that corrects the svm_migrate_copy_to_ram error handling path and updates the amdkfd driver
  • Disable the defective migration functionality in the amdkfd driver or remove the driver from the system until a patched kernel is available
  • Check the kernel distribution or vendor for an updated version that incorporates the fix and upgrade to it

Generated by OpenCVE AI on September 18, 2026 at 09:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix error path at svm_migrate_copy_to_ram If page migration from device to sys ram fails for some reasons driver needs release and unlock allocated system pages. To do that driver should use page physical address, or pfn, then get struct page*. Current driver uses dma address(for adev) that is not correct with IOMMU enabled, or even in general. The patch releases and unlocks allocated system pages based on where migration failed by struct page* of sys ram pages. Also dma_unmap correspodent system ram pages at error path.
Title drm/amdkfd: Fix error path at svm_migrate_copy_to_ram
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T09:29:08.780Z

Reserved: 2026-09-11T19:38:34.767Z

Link: CVE-2026-89810

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:46.157

Modified: 2026-09-17T10:17:04.157

Link: CVE-2026-89810

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T10:00:06Z

Weaknesses