CVE-2026-98178
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: Skip KFD mapping clear before initialization
amdgpu_amdkfd_clear_kfd_mapping() assumes that a non-NULL kfd_dev has a fully populated node array. This is not true when KFD device initialization fails after probe.
For example, kgd2kfd_device_init() sets num_nodes before checking PCIe atomics support. On Polaris systems without the required atomics, it returns before allocating nodes[0], but the kfd_dev remains attached to the amdgpu device. A later GPU reset then dereferences nodes[0]->id.
Require the authoritative KFD initialization flag before walking the node array, matching the existing KFD reset and teardown paths.
Leer descripción completaMostrar menos
(cherry picked from commit 4ac1835823c47903fbb278bbf474773c46f59edc)
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.20%
- Percentil entre todas las CVEs puntuadas: 9
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-98178",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "70cadefcc6160c575b04f763ada34c20e868d577",
"lessThan": "157d3f1db7e7e6f320daa221fae84a4c13555b6f",
"versionType": "git"
},
{
"status": "affected",
"version": "70cadefcc6160c575b04f763ada34c20e868d577",
"lessThan": "7f9caa70aef0950e06d395ca0035831214d88187",
"versionType": "git"
}
],
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_amdkfd.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "7.2"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "7.2",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "7.2.8",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc4",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_amdkfd.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-10-06T09:17:59.930",
"references": [
{
"url": "https://git.kernel.org/stable/c/157d3f1db7e7e6f320daa221fae84a4c13555b6f",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/7f9caa70aef0950e06d395ca0035831214d88187",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Skip KFD mapping clear before initialization\n\namdgpu_amdkfd_clear_kfd_mapping() assumes that a non-NULL kfd_dev\nhas a fully populated node array. This is not true when KFD device\ninitialization fails after probe.\n\nFor example, kgd2kfd_device_init() sets num_nodes before checking\nPCIe atomics support. On Polaris systems without the required atomics,\nit returns before allocating nodes[0], but the kfd_dev remains attached\nto the amdgpu device. A later GPU reset then dereferences nodes[0]->id.\n\nRequire the authoritative KFD initialization flag before walking the\nnode array, matching the existing KFD reset and teardown paths.\n\n(cherry picked from commit 4ac1835823c47903fbb278bbf474773c46f59edc)"
}
],
"lastModified": "2026-10-06T09:17:59.930",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}