« Volver al listado

CVE-2026-72091

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

accel/amdxdna: reject user command submission without a command BO

amdxdna_drm_submit_execbuf() passes the user-supplied command BO handle straight into amdxdna_cmd_submit() with drv_cmd == NULL. When the handle is AMDXDNA_INVALID_BO_HANDLE (0), the block that fetches job->cmd_bo is skipped, leaving it NULL, and no check rejects it on the user path (the !job->cmd_bo guard lives inside the != INVALID branch).

The job is then armed and pushed to the DRM scheduler. aie2_sched_job_run() takes the drv_cmd == NULL path and calls amdxdna_cmd_set_state(job->cmd_bo) -> amdxdna_gem_vmap(NULL) -> to_gobj(NULL)->dev, a NULL pointer dereference in the drm_sched worker.

Leer descripción completaMostrar menos

A process with access to the accel node on a system with a probed AMD NPU can trigger a kernel oops with a single AMDXDNA_EXEC_CMD ioctl (cmd_handles = 0).

Only internal driver commands (SYNC_DEBUG_BO / ATTACH_DEBUG_BO) legitimately pass AMDXDNA_INVALID_BO_HANDLE, and they always set drv_cmd. Reject the invalid handle for user submissions (drv_cmd == NULL) at the submit choke point so every user path is covered.

Found by 0sec automated security-research tooling (https://0sec.ai).

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-72091",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "aac243092b707bb3018e951d470cc1a9bcbaba6c",
              "lessThan": "fff6509d976f6fae423a5236391ccdbd7e0e9f06",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "aac243092b707bb3018e951d470cc1a9bcbaba6c",
              "lessThan": "261c1fe3327ad24508f54552c6366e3e4db82c15",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/accel/amdxdna/amdxdna_ctx.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.14"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.14",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.1.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/accel/amdxdna/amdxdna_ctx.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-15T06:21:23.180",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/261c1fe3327ad24508f54552c6366e3e4db82c15",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/fff6509d976f6fae423a5236391ccdbd7e0e9f06",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\naccel/amdxdna: reject user command submission without a command BO\n\namdxdna_drm_submit_execbuf() passes the user-supplied command BO handle\nstraight into amdxdna_cmd_submit() with drv_cmd == NULL. When the handle\nis AMDXDNA_INVALID_BO_HANDLE (0), the block that fetches job->cmd_bo is\nskipped, leaving it NULL, and no check rejects it on the user path (the\n!job->cmd_bo guard lives inside the != INVALID branch).\n\nThe job is then armed and pushed to the DRM scheduler.\naie2_sched_job_run() takes the drv_cmd == NULL path and calls\namdxdna_cmd_set_state(job->cmd_bo) -> amdxdna_gem_vmap(NULL) ->\nto_gobj(NULL)->dev, a NULL pointer dereference in the drm_sched worker.\nA process with access to the accel node on a system with a probed AMD NPU\ncan trigger a kernel oops with a single AMDXDNA_EXEC_CMD ioctl\n(cmd_handles = 0).\n\nOnly internal driver commands (SYNC_DEBUG_BO / ATTACH_DEBUG_BO)\nlegitimately pass AMDXDNA_INVALID_BO_HANDLE, and they always set drv_cmd.\nReject the invalid handle for user submissions (drv_cmd == NULL) at the\nsubmit choke point so every user path is covered.\n\nFound by 0sec automated security-research tooling (https://0sec.ai)."
    }
  ],
  "lastModified": "2026-08-17T06:18:08.050",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}