Description
In the Linux kernel, the following vulnerability has been resolved:

drm/amdkfd: Add TLB flush after MES queue eviction/suspension

MES (Micro Engine Scheduler) does not perform heavy-weight TLB
invalidation after unmapping queues, unlike HWS which does this
automatically. This causes a race condition where in-flight DMA
descriptors can access memory that has been unmapped, leading to page
faults and GPU queue hangs during SVM page migration.

The issue manifests as KFDSVMRangeTest.MultiThreadMigrationTest
failures on gfx1151 (Strix Point) with XNACK mode 1 enabled - the GPU
compute queue hangs with packets submitted but never consumed.

Add kfd_flush_tlb() calls after MES queue removal in two locations:
- evict_process_queues_cpsch(): after all queues removed during eviction
- suspend_queues(): after debug/criu queue suspension (with mem_fence barrier)

This ensures all in-flight memory accesses from unmapped queues are
flushed before memory is freed or migrated.

(cherry picked from commit f5c4f88e0f9c45a8fb9dfac0c1df726c95e41b77)
Published: 2026-09-16
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via GPU queue hang caused by race condition
Action: Apply Patch
AI Analysis

Impact

A race condition in the Linux kernel’s AMD KFD driver allows in‑flight DMA descriptors to access memory that has already been unmapped during MES queue eviction or suspension, leading to page faults and GPU compute queue hangs. This interruption can suspend GPU workloads and effectively deny service to applications relying on the graphics subsystem.

Affected Systems

Linux kernel versions lacking the recent kernel Float‑based TLB flush after MES queue removal in the drm/amdkfd component are affected. The vulnerability applies to any system using this component prior to the inclusion of the patch in the kernel source tree.

Risk and Exploitability

The vulnerability scores a CVSS of 8.8, indicating high severity, but the EPSS score is below 1%, meaning the likelihood of exploitation is very low. It is not listed in CISA’s KEV catalog. The attack vector is likely local and requires the ability to drive GPU queues, so an attacker would need to execute privileged or high‑level code that interacts with the graphics driver to trigger the race.

Generated by OpenCVE AI on September 18, 2026 at 09:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the kfd_flush_tlb patch (commit f5c4f88e0f9c45a8fb9dfac0c1df726c95e41b77).
  • Upgrade the AMD KFD driver to a release that implements TLB flushing after MES queue eviction and suspension.
  • If a kernel upgrade is not immediately possible, avoid using graphics queues that trigger MES eviction by disabling features such as SVM page migration or XNACK mode 1 until the patch is applied.

Generated by OpenCVE AI on September 18, 2026 at 09:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362
CWE-416

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Add TLB flush after MES queue eviction/suspension MES (Micro Engine Scheduler) does not perform heavy-weight TLB invalidation after unmapping queues, unlike HWS which does this automatically. This causes a race condition where in-flight DMA descriptors can access memory that has been unmapped, leading to page faults and GPU queue hangs during SVM page migration. The issue manifests as KFDSVMRangeTest.MultiThreadMigrationTest failures on gfx1151 (Strix Point) with XNACK mode 1 enabled - the GPU compute queue hangs with packets submitted but never consumed. Add kfd_flush_tlb() calls after MES queue removal in two locations: - evict_process_queues_cpsch(): after all queues removed during eviction - suspend_queues(): after debug/criu queue suspension (with mem_fence barrier) This ensures all in-flight memory accesses from unmapped queues are flushed before memory is freed or migrated. (cherry picked from commit f5c4f88e0f9c45a8fb9dfac0c1df726c95e41b77)
Title drm/amdkfd: Add TLB flush after MES queue eviction/suspension
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T09:29:10.105Z

Reserved: 2026-09-11T19:38:34.768Z

Link: CVE-2026-89811

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:46.267

Modified: 2026-09-17T10:17:04.273

Link: CVE-2026-89811

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T09:30:06Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

  • CWE-416

    Use After Free