Description
In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu: clamp the isolation index for rings outside a partition

adev->isolation[] has one slot per partition, but a ring that is not
assigned to one keeps AMDGPU_XCP_NO_PARTITION, which is ~0, so indexing
the array with it is out of bounds. SDMA submissions hit this on both
the isolation enforcement and the VM flush path and trip UBSAN.

Fall back to the first slot the way the cleaner shader path already
does, and stop taking the address before the ring type check that makes
it relevant.
Published: 2026-09-16
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Patch Immediately
AI Analysis

Impact

An out‑of‑bounds indexing bug in the Linux AMDGPU DRM driver can cause undefined kernel behavior when a ring is not assigned to a partition. The isolation index used for such rings is a special value that refers to a non‑existent array slot, leading to a memory corruption trigger that UBSAN reports and which can result in a kernel panic or data corruption. This flaw could be used to gain elevated privileges or destabilize the system.

Affected Systems

All Linux kernels that include the amdgpu driver before the fix are vulnerable; the issue was addressed in the kernel mainline around the commit from which the patch is derived. The vulnerability applies to every distribution that ships an unpatched AMDGPU driver.

Risk and Exploitability

The CVSS score of 7.8 indicates a moderate‑to‑high severity, yet the EPSS score is less than 1%, suggesting a low probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog, and no public exploits have been reported. The most likely attack scenario requires access to the victim’s machine or a privileged context that can submit SDMA commands, meaning local or system‑level compromise is required.

Generated by OpenCVE AI on September 18, 2026 at 09:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that incorporates the AMDGPU isolation index clamping fix
  • If an immediate kernel update is not feasible, disable AMDGPU or SDMA usage to prevent triggering the out‑of‑bounds access
  • Conduct kernel integrity checks or taint verification to confirm that the patched driver is in use

Generated by OpenCVE AI on September 18, 2026 at 09:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-125

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: clamp the isolation index for rings outside a partition adev->isolation[] has one slot per partition, but a ring that is not assigned to one keeps AMDGPU_XCP_NO_PARTITION, which is ~0, so indexing the array with it is out of bounds. SDMA submissions hit this on both the isolation enforcement and the VM flush path and trip UBSAN. Fall back to the first slot the way the cleaner shader path already does, and stop taking the address before the ring type check that makes it relevant.
Title drm/amdgpu: clamp the isolation index for rings outside a partition
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T09:29:14.022Z

Reserved: 2026-09-11T19:38:34.768Z

Link: CVE-2026-89814

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:46.610

Modified: 2026-09-17T10:17:04.577

Link: CVE-2026-89814

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T09:15:06Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-125

    Out-of-bounds Read