« Volver al listado

CVE-2026-89809

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

drm/amdkfd: fix scope of mqd_mgr dereference in pqm_debugfs_mqds

Reading /sys/kernel/debug/kfd/mqds while a process holds an active KFD queue triggers a NULL pointer dereference because the for loop that calls mqd_mgr->debugfs_show_mqd() is incorrectly placed outside the if (pqn->q) block that initializes mqd_mgr.

The queue list can contain entries where pqn->q is NULL (kernel queues where only pqn->kq is valid). In the original code:

When iterating over a queue node where pqn->q is NULL: 1. The if (pqn->q) block is skipped 2. mqd_mgr remains uninitialized (NULL from declaration) 3. The for loop executes anyway 4. mqd_mgr->debugfs_show_mqd(m, mqd) dereferences NULL

Leer descripción completaMostrar menos

The crash manifests as:

Fix by moving the for loop inside the if (pqn->q) block, so mqd_mgr and related variables are only used when properly initialized.

(cherry picked from commit 8bfe29d5c798940f797aa24135d2734c3ffce9de)

Detalles técnicos trazas, registros y código del informe original
  if (pqn->q) {
      ...
      mqd_mgr = q->device->dqm->mqd_mgrs[mqd_type];
      size = mqd_mgr->mqd_stride(...);
  }

  for (xcc = 0; xcc < num_xccs; xcc++) {  // WRONG: outside if block
      mqd = q->mqd + size * xcc;
      r = mqd_mgr->debugfs_show_mqd(m, mqd);
  }

  BUG: kernel NULL pointer dereference, address: 0000000000000000
  #PF: supervisor instruction fetch in kernel mode
  RIP: 0010:0x0
  Call Trace:
   pqm_debugfs_mqds+0x10c/0x1d0 [amdgpu]
   kfd_debugfs_mqds_by_process+0x9b/0x110 [amdgpu]
   seq_read_iter+0x132/0x4b0
   ...

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-89809",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "e1b73b64271d706079370b58b81292dafd373163",
              "lessThan": "58e866711b234571b0ce342c43d153a4786b32b8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e1b73b64271d706079370b58b81292dafd373163",
              "lessThan": "012a026bae0212952b423a842b7e2c0bf21f8e7a",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/gpu/drm/amd/amdkfd/kfd_process_queue_manager.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7.0"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "7.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/gpu/drm/amd/amdkfd/kfd_process_queue_manager.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-16T11:16:46.047",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/012a026bae0212952b423a842b7e2c0bf21f8e7a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/58e866711b234571b0ce342c43d153a4786b32b8",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: fix scope of mqd_mgr dereference in pqm_debugfs_mqds\n\nReading /sys/kernel/debug/kfd/mqds while a process holds an active KFD\nqueue triggers a NULL pointer dereference because the for loop that\ncalls mqd_mgr->debugfs_show_mqd() is incorrectly placed outside the\nif (pqn->q) block that initializes mqd_mgr.\n\nThe queue list can contain entries where pqn->q is NULL (kernel queues\nwhere only pqn->kq is valid). In the original code:\n\n  if (pqn->q) {\n      ...\n      mqd_mgr = q->device->dqm->mqd_mgrs[mqd_type];\n      size = mqd_mgr->mqd_stride(...);\n  }\n\n  for (xcc = 0; xcc < num_xccs; xcc++) {  // WRONG: outside if block\n      mqd = q->mqd + size * xcc;\n      r = mqd_mgr->debugfs_show_mqd(m, mqd);\n  }\n\nWhen iterating over a queue node where pqn->q is NULL:\n1. The if (pqn->q) block is skipped\n2. mqd_mgr remains uninitialized (NULL from declaration)\n3. The for loop executes anyway\n4. mqd_mgr->debugfs_show_mqd(m, mqd) dereferences NULL\n\nThe crash manifests as:\n\n  BUG: kernel NULL pointer dereference, address: 0000000000000000\n  #PF: supervisor instruction fetch in kernel mode\n  RIP: 0010:0x0\n  Call Trace:\n   pqm_debugfs_mqds+0x10c/0x1d0 [amdgpu]\n   kfd_debugfs_mqds_by_process+0x9b/0x110 [amdgpu]\n   seq_read_iter+0x132/0x4b0\n   ...\n\nFix by moving the for loop inside the if (pqn->q) block, so mqd_mgr\nand related variables are only used when properly initialized.\n\n(cherry picked from commit 8bfe29d5c798940f797aa24135d2734c3ffce9de)"
    }
  ],
  "lastModified": "2026-09-17T10:17:04.047",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}