CVE-2026-68102
Received Received - Intake

Memory Leak in AMDGPU Linux Kernel Driver

Vulnerability report for CVE-2026-68102, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-10

Last updated on: 2026-08-10

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix aperture mapping leak amdgpu_pci_remove() calls drm_dev_unplug() before invoking the driver fini routines. This causes drm_dev_enter() in amdgpu_ttm_fini() to always return false, so iounmap(aper_base_kaddr) never runs on normal driver unload, leaving an orphaned entry in the x86 PAT interval tree. On connected_to_cpu hardware, the aperture is mapped write-back (WB) via ioremap_cache(). On reload, IP discovery calls memremap(..., MEMREMAP_WC) over the same range. The WC vs WB conflict causes: ioremap error for 0x..., requested 0x1, got 0x0 amdgpu: discovery failed: -2 Fix by switching to devres-managed mappings so cleanup is guaranteed regardless of drm_dev_enter() state: - connected_to_cpu path: devm_memremap(MEMREMAP_WB). For IORESOURCE_SYSTEM_RAM ranges this takes the try_ram_remap() shortcut, returning __va(offset) from the existing kernel direct map. No new ioremap VA or PAT entry is created, so there is nothing to orphan. - dGPU path: devm_ioremap_wc() registers iounmap() as a devres action, guaranteeing cleanup at device_del() time. Also remove iounmap(aper_base_kaddr) from amdgpu_device_unmap_mmio() since the mapping is now devres-owned. v2: Remove redundant x86_64 guard (Lijo) (cherry picked from commit d871e99879cb5fd1fa798b006b4888887e63a17a)

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-10
Last Modified
2026-08-10
Generated
2026-08-10
AI Q&A
2026-08-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
amd amdgpu *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a memory mapping leak in the AMD GPU driver. When the driver is unloaded, a cleanup function fails to run properly, leaving an orphaned entry in the system's memory mapping table. This can cause conflicts when the driver is reloaded, leading to errors during hardware initialization.

Detection Guidance

This vulnerability is specific to the Linux kernel's AMDGPU driver and does not have network-based detection methods. To detect it, check kernel logs for errors related to amdgpu or aperture mapping issues during driver unload or reload. Commands like dmesg | grep amdgpu or journalctl -k | grep amdgpu may reveal related errors.

Impact Analysis

If you use a system with an AMD GPU, this vulnerability could cause system instability or failure when the GPU driver is unloaded and reloaded. This might result in crashes, errors during boot, or loss of graphics functionality until the system is rebooted.

Mitigation Strategies

Update the Linux kernel to a patched version that includes the fix for this vulnerability. The issue is resolved in the kernel by switching to devres-managed mappings for the AMDGPU driver. Check your distribution's updates or kernel.org for the latest stable release.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-68102. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart