« Volver al listado

CVE-2026-98270

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu: check ras and obj before dereference

nbio_v7_9_handle_ras_controller_intr_no_bifring() dereferences ras and obj without checking either for NULL. Both amdgpu_ras_get_context() and amdgpu_ras_find_obj() can return NULL, e.g. during the window between adev->nbio.ras being set (early in amdgpu_ras_init(), by design, to enable the fatal-error interrupt as soon as possible) and the PCIE_BIF ras object actually being created in RAS late_init. Any interrupt in that window crashes in hard-IRQ context.

This is analogous to commit d190b459b2a4 ("drm/amdgpu: the warning dereferencing obj for nbio_v7_4"), which fixed the same issue in the nbio_v7_4 handler.

Leer descripción completaMostrar menos

Found by Linux Verification Center (linuxtesting.org) with SVACE.

(cherry picked from commit c7071767a50a32ed727cf800ac84372429e3b4b3)

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98270",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7692e1ee2446fd1940b5caa6e09779504a58881a",
              "lessThan": "b7c7f07a40037514f8e890aa00f8d7b196d680cf",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7692e1ee2446fd1940b5caa6e09779504a58881a",
              "lessThan": "fc5f845a291fc8175e6857cd6ad042818da192e8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7692e1ee2446fd1940b5caa6e09779504a58881a",
              "lessThan": "37583946d8751f8e285c467d770ac0b609b82a23",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7692e1ee2446fd1940b5caa6e09779504a58881a",
              "lessThan": "315c22712715491f0dfafdaf2c2b437540e68702",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7692e1ee2446fd1940b5caa6e09779504a58881a",
              "lessThan": "723d4dc628d764b19cf9efca14b82cca5ff020c9",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/gpu/drm/amd/amdgpu/nbio_v7_9.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.6"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.6",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.112",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.54",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/gpu/drm/amd/amdgpu/nbio_v7_9.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-10-06T09:18:16.487",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/315c22712715491f0dfafdaf2c2b437540e68702",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/37583946d8751f8e285c467d770ac0b609b82a23",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/723d4dc628d764b19cf9efca14b82cca5ff020c9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b7c7f07a40037514f8e890aa00f8d7b196d680cf",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/fc5f845a291fc8175e6857cd6ad042818da192e8",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: check ras and obj before dereference\n\nnbio_v7_9_handle_ras_controller_intr_no_bifring() dereferences ras and obj\nwithout checking either for NULL. Both amdgpu_ras_get_context() and\namdgpu_ras_find_obj() can return NULL, e.g. during the window between\nadev->nbio.ras being set (early in amdgpu_ras_init(), by design, to\nenable the fatal-error interrupt as soon as possible) and the PCIE_BIF\nras object actually being created in RAS late_init. Any interrupt in that\nwindow crashes in hard-IRQ context.\n\nThis is analogous to commit d190b459b2a4 (\"drm/amdgpu: the warning\ndereferencing obj for nbio_v7_4\"), which fixed the same issue in the\nnbio_v7_4 handler.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.\n\n(cherry picked from commit c7071767a50a32ed727cf800ac84372429e3b4b3)"
    }
  ],
  "lastModified": "2026-10-06T09:18:16.487",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}