Description
In the Linux kernel, the following vulnerability has been resolved:

accel/amdxdna: return early from a zero-length flush

SYNC_BO does not constrain its size, so a request for zero bytes reaches
drm_clflush_virt_range(), which ends with an unconditional
clflushopt(end - 1). For an empty range that is the byte before the
mapping, and abo->mem.kva comes from vmap(), so the access lands in the
guard page below the vmalloc area and faults:

BUG: unable to handle page fault for address: ffffd16fbbc70fff
#PF: supervisor read access in kernel mode
Oops: Oops: 0000 [#1] SMP NOPTI
CPU: 7 UID: 1000 Comm: sync_bo_probe
RIP: 0010:drm_clflush_virt_range+0x3c/0x70
Call Trace:
amdxdna_drm_sync_bo_ioctl+0x124/0x430 [amdxdna]
drm_ioctl+0x301/0x4c0
__x64_sys_ioctl+0x115/0x2f0
do_syscall_64+0xa6/0x3d0

Any process that can open the render node can do this. Reproduced 3 of 3
times on a Strix Point NPU (1022:17f0), by calling SYNC_BO with size 0 on
an AMDXDNA_BO_SHARE object. The import arm takes the same request but
flushes the whole scatterlist, so it survives it.

Nothing needs flushing for an empty range, so answer before choosing a
path.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel Crash (Denial of Service)
Action: Immediate Patch
AI Analysis

Impact

The Linux kernel's AMDX DNA driver incorrectly handles a SYNC_BO ioctl request that specifies a zero-length buffer. The driver forwards the request to drm_clflush_virt_range, which calculates an interval ending at the start of the buffer. Because the interval is empty, the function performs an unconditional clflushopt on the address immediately before the buffer. In a zero-size case this address lands in the guard page below the vmalloc area, causing a page fault and a kernel panic. Any process that can open a render node can issue such an ioctl, which means an ordinary local user can trigger a full system crash.

Affected Systems

Affected systems include any Linux kernel running the AMD XDNA GPU driver, such as the Strix Point NPU (1022:17f0) or other AMD XDNA devices. The vulnerability is present in kernels before the fix commit, so all releases prior to the patch are affected.

Risk and Exploitability

The EPSS score is below 1%, indicating a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers can trigger the crash from any user that can access a render node; no network or privilege escalation is required. While the fault causes a complete kernel panic, the lack of a known remote or high-privilege exploit keeps the overall risk moderate, but the defect remains a serious denial‑of‑service vector for local users.

Generated by OpenCVE AI on September 18, 2026 at 04:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a Linux kernel update that contains the AMDX DNA sync buffer clflush fix (e.g., the commit that adds bounds checking to drm_clflush_virt_range).
  • Restrict write access to /dev/dri/render* devices so that only privileged users or processes can invoke SYNC_BO, using udev rules or ACLs.
  • As a temporary workaround, patch or configure the AMD XDNA driver to reject SYNC_BO requests with a zero size or to skip the flush when the requested range is empty.

Generated by OpenCVE AI on September 18, 2026 at 04:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: return early from a zero-length flush SYNC_BO does not constrain its size, so a request for zero bytes reaches drm_clflush_virt_range(), which ends with an unconditional clflushopt(end - 1). For an empty range that is the byte before the mapping, and abo->mem.kva comes from vmap(), so the access lands in the guard page below the vmalloc area and faults: BUG: unable to handle page fault for address: ffffd16fbbc70fff #PF: supervisor read access in kernel mode Oops: Oops: 0000 [#1] SMP NOPTI CPU: 7 UID: 1000 Comm: sync_bo_probe RIP: 0010:drm_clflush_virt_range+0x3c/0x70 Call Trace: amdxdna_drm_sync_bo_ioctl+0x124/0x430 [amdxdna] drm_ioctl+0x301/0x4c0 __x64_sys_ioctl+0x115/0x2f0 do_syscall_64+0xa6/0x3d0 Any process that can open the render node can do this. Reproduced 3 of 3 times on a Strix Point NPU (1022:17f0), by calling SYNC_BO with size 0 on an AMDXDNA_BO_SHARE object. The import arm takes the same request but flushes the whole scatterlist, so it survives it. Nothing needs flushing for an empty range, so answer before choosing a path.
Title accel/amdxdna: return early from a zero-length flush
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:32:55.928Z

Reserved: 2026-09-11T19:38:34.779Z

Link: CVE-2026-89978

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:08.667

Modified: 2026-09-16T11:17:08.667

Link: CVE-2026-89978

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T04:15:02Z

Weaknesses