Description
In the Linux kernel, the following vulnerability has been resolved:

media: amd: isp4: release partial allocations in isp4if_alloc_fw_gpumem()

isp4if_alloc_fw_gpumem() allocates several GPU memory pools in sequence.
If one of them fails, it jumps to error_no_memory and returns -ENOMEM
without releasing the pools that were already allocated, leaking them.

Release the already-allocated pools before returning. isp4if_gpu_mem_free()
is a no-op on pools that were not allocated, so calling
isp4if_dealloc_fw_gpumem() here safely frees exactly the pools that
succeeded.

isp4if_gpu_mem_free() previously logged an error for a NULL entry, which
is a normal case during partial-allocation cleanup, so make it silent.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Resource Exhaustion (Memory Leak)
Action: Patch
AI Analysis

Impact

The issue concerns the isp4if_alloc_fw_gpumem function in the Linux kernel, which allocates multiple GPU memory pools sequentially. If any allocation fails, the function returns an ENOMEM error without releasing previously allocated pools, leaving them in an allocated state. This leak can accumulate over time, exhausting kernel memory and potentially leading to degraded performance or system instability. The vulnerability is a memory leak (CWE‑401) and a broader resource management error (CWE‑399).

Affected Systems

Affected systems are any Linux kernel installations that use the AMD ISP4 media subsystem. No specific kernel version is supplied, so the flaw may exist in all releases containing this function until the patch in commits a1f8750668e552837df781783909f2f680958006 and fea97ee13c5332f67850733d6cefc1fe99460bde is applied.

Risk and Exploitability

The EPSS score of less than 1% indicates a very low likelihood of exploitation. The issue is not listed in CISA’s KEV catalog, suggesting no known active exploit. An attacker would need local access to the kernel or the ability to invoke the ISP4 firmware allocation routine, possibly through privileged media operations. Such a local approach would result in a gradual depletion of kernel memory over time, but would not allow immediate code execution. The overall risk is low to medium, primarily associated with resource exhaustion if the failure conditions are repeatedly triggered.

Generated by OpenCVE AI on September 19, 2026 at 03:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a release containing the commits that release previously allocated GPU memory pools.
  • If an immediate kernel upgrade is not possible, avoid forcing allocation failures or reboot the system to clear leaked memory pools.
  • Consider disabling the AMD ISP4 media driver if the device is not in use to prevent the vulnerable routine from executing.

Generated by OpenCVE AI on September 19, 2026 at 03:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-399
CWE-401

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: media: amd: isp4: release partial allocations in isp4if_alloc_fw_gpumem() isp4if_alloc_fw_gpumem() allocates several GPU memory pools in sequence. If one of them fails, it jumps to error_no_memory and returns -ENOMEM without releasing the pools that were already allocated, leaking them. Release the already-allocated pools before returning. isp4if_gpu_mem_free() is a no-op on pools that were not allocated, so calling isp4if_dealloc_fw_gpumem() here safely frees exactly the pools that succeeded. isp4if_gpu_mem_free() previously logged an error for a NULL entry, which is a normal case during partial-allocation cleanup, so make it silent.
Title media: amd: isp4: release partial allocations in isp4if_alloc_fw_gpumem()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:07:43.787Z

Reserved: 2026-09-11T19:38:34.795Z

Link: CVE-2026-90239

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:19.860

Modified: 2026-09-17T17:17:19.860

Link: CVE-2026-90239

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T08:30:16Z

Weaknesses