Description
In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu: Fix init ordering in amdgpu_vram_mgr_init()

drmm_cgroup_register_region() is called before INIT_LIST_HEAD() and
gpu_buddy_init() in amdgpu_vram_mgr_init(). If it fails, the function
returns early and bypasses those initializations.

Since adev->mman.initialized is set to true before amdgpu_vram_mgr_init()
is called, a failure triggers amdgpu_ttm_fini(), which calls
amdgpu_vram_mgr_fini(), which then:

- Calls list_for_each_entry_safe() on reservations_pending and
reserved_pages, whose list_head::next pointers are zero-initialized
(NULL). The loop does not recognize them as empty and dereferences NULL.

- Calls gpu_buddy_fini(), which iterates free_trees[] unconditionally
via for_each_free_tree(). Since mm->free_trees is NULL
(never allocated), this dereferences NULL.

Both result in a kernel panic on the module load error path.

Fix by moving drmm_cgroup_register_region() to after the list and buddy
allocator are fully initialized, so the teardown path is safe to run.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The amdgpu driver in the Linux kernel contains a bug where the VRAM manager initialization routine performs region registration before fully setting up internal data structures. If region registration fails, the cleanup path is entered with uninitialized list heads and buddy allocator structures, causing null pointer dereferences and a kernel panic. An attacker who can cause the driver to be initialized under those conditions would be able to crash the system, resulting in a denial‑of‑service and potentially allowing further exploitation through the kernel panic.

Affected Systems

Linux kernels that include the AMDGPU driver before the commit that corrected the init ordering. The vulnerability is present in all kernel releases lacking the patch, which affect machines that load the amdgpu driver during boot or when a GPU device is accessed.

Risk and Exploitability

The EPSS score is less than 1 %, indicating a low probability of automated exploitation, and the issue is not listed in the CISA KEV catalog. Nevertheless, the defect causes a kernel panic, a high‑severity denial of service. Because the flaw manifests during driver load, it can be triggered by early boot activities or GPU usage, making it potentially reachable by local users with sufficient privileges or specialized hardware access. The overall risk is moderate to high for systems that have not yet applied the patch.

Generated by OpenCVE AI on September 18, 2026 at 09:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to include the patch that moves drmm_cgroup_register_region() after VRAM manager initialization.
  • If a kernel upgrade is not immediately available, manually apply the upstream patch from the linked Git commits and rebuild the kernel.
  • After applying the patch or upgrading, reboot the system and confirm that the amdgpu driver loads without crashing.

Generated by OpenCVE AI on September 18, 2026 at 09:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476
CWE-665

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix init ordering in amdgpu_vram_mgr_init() drmm_cgroup_register_region() is called before INIT_LIST_HEAD() and gpu_buddy_init() in amdgpu_vram_mgr_init(). If it fails, the function returns early and bypasses those initializations. Since adev->mman.initialized is set to true before amdgpu_vram_mgr_init() is called, a failure triggers amdgpu_ttm_fini(), which calls amdgpu_vram_mgr_fini(), which then: - Calls list_for_each_entry_safe() on reservations_pending and reserved_pages, whose list_head::next pointers are zero-initialized (NULL). The loop does not recognize them as empty and dereferences NULL. - Calls gpu_buddy_fini(), which iterates free_trees[] unconditionally via for_each_free_tree(). Since mm->free_trees is NULL (never allocated), this dereferences NULL. Both result in a kernel panic on the module load error path. Fix by moving drmm_cgroup_register_region() to after the list and buddy allocator are fully initialized, so the teardown path is safe to run.
Title drm/amdgpu: Fix init ordering in amdgpu_vram_mgr_init()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:31:00.827Z

Reserved: 2026-09-11T19:38:34.769Z

Link: CVE-2026-89828

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:49.493

Modified: 2026-09-16T11:16:49.493

Link: CVE-2026-89828

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T09:45:06Z

Weaknesses