« Volver al listado

CVE-2026-97928

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu: skip the VMID 0 flush for VRAM

Clear-on-release only runs on VRAM, which amdgpu_ttm_map_buffer() reaches via its direct MC address without programming a GART window, yet the wipe still forces a VMID 0 flush. On GFX11 (e.g. Navi33) that spurious SDMA flush can wedge the engine; only flush when a GART window is actually used.

(cherry picked from commit a306e406e570b74318ff7d80e5b07b540ca1d3a9)

Detalles técnicos trazas, registros y código del informe original
v2: Let amdgpu_ttm_map_buffer() return whether the VMID 0 flush is needed,
    and drive the clear and copy paths from that. (Christian)
v3: Make the vm_needs_flush output parameter mandatory instead of
    allowing NULL. (Christian)

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-97928",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "a68c7eaa7a8ffdec9287ba1561a668d674c20a13",
              "lessThan": "241d7450cf75969cea450eb3e740cb9682f69c2f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "a68c7eaa7a8ffdec9287ba1561a668d674c20a13",
              "lessThan": "87ceb8cba73d0b3c4025ff42495bccd8164acaed",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/gpu/drm/amd/amdgpu/amdgpu_ttm.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.10"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.10",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc3",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/gpu/drm/amd/amdgpu/amdgpu_ttm.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:20.063",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/241d7450cf75969cea450eb3e740cb9682f69c2f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/87ceb8cba73d0b3c4025ff42495bccd8164acaed",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: skip the VMID 0 flush for VRAM\n\nClear-on-release only runs on VRAM, which amdgpu_ttm_map_buffer() reaches\nvia its direct MC address without programming a GART window, yet the wipe\nstill forces a VMID 0 flush. On GFX11 (e.g. Navi33) that spurious SDMA\nflush can wedge the engine; only flush when a GART window is actually used.\n\nv2: Let amdgpu_ttm_map_buffer() return whether the VMID 0 flush is needed,\n    and drive the clear and copy paths from that. (Christian)\nv3: Make the vm_needs_flush output parameter mandatory instead of\n    allowing NULL. (Christian)\n\n(cherry picked from commit a306e406e570b74318ff7d80e5b07b540ca1d3a9)"
    }
  ],
  "lastModified": "2026-09-25T11:17:20.063",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}