Description
In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu: avoid force-completing uninitialized UVD rings

uvd_v7_0_sw_init() does not initialize the UVD decode ring for an
SR-IOV VF. However, amdgpu_uvd_resume() unconditionally force-completes
the decode ring when restoring its fence sequence.

Skip fence completion when the fence driver is not initialized.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via kernel crash
Action: Apply Patch
AI Analysis

Impact

The flaw in the Linux kernel's amdgpu driver causes the system to force‑complete a UVD decode ring that has never been initialized when an SR‑IOV virtual function is resumed. Because the ring buffer state is bogus, the forced completion can corrupt kernel memory or trigger an assertion, potentially leading to a kernel crash or denial of service. The weakness stems from improper initialization and subsequent blind operation on uninitialized data.

Affected Systems

This issue affects the Linux kernel and, more specifically, the amdgpu device driver on systems that enable SR‑IOV to create virtual functions. The patch is included in kernel commits identified in the provided references, but no explicit kernel version range is supplied, so any kernel build prior to those commits is potentially vulnerable. The vulnerability is limited to the virtual function context; standard physical GPUs are unaffected.

Risk and Exploitability

The EPSS score is below 1 % and the CVE is not listed in the CISA KEV catalog, indicating a low probability of widespread exploitation. Nevertheless, the flaw allows an attacker to crash the kernel if they can trigger a resume of an uninitialized UVD ring, which typically requires kernel or root access. The attack vector is therefore inferred as a local privilege escalation or kernel exploit rather than remote abuse, but because it directly causes a denial of service, it remains a noteworthy risk for environments that rely on SR‑IOV GPU sharing.

Generated by OpenCVE AI on September 18, 2026 at 09:05 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel release or backport the amdgpu ring‑initialization patch to the kernel.
  • If the kernel cannot be updated immediately, disable SR‑IOV virtual functions for AMD GPUs or configure the driver to skip ring completion when the fence driver is not active, as described in the fix.
  • Monitor kernel logs for UVD ring completion warnings or crashes and verify that the patch has been applied by inspecting commit IDs 6760f5cb and 967a1794 in the source tree.

Generated by OpenCVE AI on September 18, 2026 at 09:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 11:15:00 +0000


Mon, 21 Sep 2026 13:30:00 +0000


Fri, 18 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: avoid force-completing uninitialized UVD rings uvd_v7_0_sw_init() does not initialize the UVD decode ring for an SR-IOV VF. However, amdgpu_uvd_resume() unconditionally force-completes the decode ring when restoring its fence sequence. Skip fence completion when the fence driver is not initialized.
Title drm/amdgpu: avoid force-completing uninitialized UVD rings
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-10-03T10:56:43.424Z

Reserved: 2026-09-11T19:38:34.769Z

Link: CVE-2026-89827

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:49.380

Modified: 2026-10-03T11:17:43.970

Link: CVE-2026-89827

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T09:15:06Z

Weaknesses