« Volver al listado

CVE-2026-68275

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu: check amdgpu_vm_bo_find() result in GET_MAPPING_INFO

The AMDGPU_GEM_OP_GET_MAPPING_INFO path of amdgpu_gem_op_ioctl() looks up the bo_va for the buffer object in the caller's VM via amdgpu_vm_bo_find(), but uses the returned pointer without checking it.

amdgpu_vm_bo_find() returns NULL when the BO has no bo_va in that VM, which is the normal case for a BO that has never been mapped. The result is fed straight into amdgpu_vm_bo_va_for_each_valid_mapping(), which expands to list_for_each_entry(mapping, &(bo_va)->valids, list) and dereferences bo_va, causing a NULL pointer dereference.

Leer descripción completaMostrar menos

This is reachable by any process able to issue the ioctl (render group) simply by requesting mapping info for an unmapped BO.

Return -ENOENT when no bo_va is found, jumping to out_exec so the drm_exec context and GEM object reference are released.

(cherry picked from commit 528b19377affc1cc7362a70a254c1dda793595f9)

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-68275",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4d82724f7f2b847eb0454b1aab5450545b39abd4",
              "lessThan": "ddba17b3dfa0efc80d6c98621c2fb7af66adb622",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4d82724f7f2b847eb0454b1aab5450545b39abd4",
              "lessThan": "9faf4c66edb6bcb8ca0465c3a4868bb7f278cd31",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4d82724f7f2b847eb0454b1aab5450545b39abd4",
              "lessThan": "93475c34111916df71c63e510fc52db01351f809",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/gpu/drm/amd/amdgpu/amdgpu_gem.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.18"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.18",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.42",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/gpu/drm/amd/amdgpu/amdgpu_gem.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-10T13:20:16.583",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/93475c34111916df71c63e510fc52db01351f809",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9faf4c66edb6bcb8ca0465c3a4868bb7f278cd31",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ddba17b3dfa0efc80d6c98621c2fb7af66adb622",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: check amdgpu_vm_bo_find() result in GET_MAPPING_INFO\n\nThe AMDGPU_GEM_OP_GET_MAPPING_INFO path of amdgpu_gem_op_ioctl() looks\nup the bo_va for the buffer object in the caller's VM via\namdgpu_vm_bo_find(), but uses the returned pointer without checking it.\n\namdgpu_vm_bo_find() returns NULL when the BO has no bo_va in that VM,\nwhich is the normal case for a BO that has never been mapped. The result\nis fed straight into amdgpu_vm_bo_va_for_each_valid_mapping(), which\nexpands to list_for_each_entry(mapping, &(bo_va)->valids, list) and\ndereferences bo_va, causing a NULL pointer dereference.\n\nThis is reachable by any process able to issue the ioctl (render group)\nsimply by requesting mapping info for an unmapped BO.\n\nReturn -ENOENT when no bo_va is found, jumping to out_exec so the\ndrm_exec context and GEM object reference are released.\n\n(cherry picked from commit 528b19377affc1cc7362a70a254c1dda793595f9)"
    }
  ],
  "lastModified": "2026-08-17T05:18:30.090",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}