CVE-2026-98178
Received Received - Intake

AMDGPU KFD Memory Access Flaw in Linux Kernel

Vulnerability report for CVE-2026-98178, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Skip KFD mapping clear before initialization amdgpu_amdkfd_clear_kfd_mapping() assumes that a non-NULL kfd_dev has a fully populated node array. This is not true when KFD device initialization fails after probe. For example, kgd2kfd_device_init() sets num_nodes before checking PCIe atomics support. On Polaris systems without the required atomics, it returns before allocating nodes[0], but the kfd_dev remains attached to the amdgpu device. A later GPU reset then dereferences nodes[0]->id. Require the authoritative KFD initialization flag before walking the node array, matching the existing KFD reset and teardown paths. (cherry picked from commit 4ac1835823c47903fbb278bbf474773c46f59edc)

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
Linux Linux 7.2
Linux Linux 70cadefcc6160c575b04f763ada34c20e868d577
Linux Linux 70cadefcc6160c575b04f763ada34c20e868d577

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a flaw in the AMD GPU driver (amdgpu) related to the KFD (Kernel Fusion Driver) mapping. The function amdgpu_amdkfd_clear_kfd_mapping() incorrectly assumes that a non-NULL kfd_dev has a fully populated node array, which may not be true if KFD device initialization fails after probing. This can lead to a situation where nodes[0] is dereferenced even though it was never allocated, causing potential system instability or crashes.

Detection Guidance

This vulnerability is specific to the Linux kernel's AMD GPU driver (amdgpu) and KFD (Kernel Fusion Driver) interaction. Detection requires checking kernel logs for GPU reset errors or KFD initialization failures. Look for messages like 'nodes[0]->id' dereference errors in dmesg or system logs after GPU operations.

Impact Analysis

If you use a system with an AMD GPU and the Linux kernel, this vulnerability could cause system crashes or instability during GPU operations, particularly during GPU resets. It may lead to kernel panics or unexpected behavior if the KFD initialization fails and later operations attempt to access unallocated memory.

Mitigation Strategies

Update the Linux kernel to a patched version that includes the fix for this issue. Monitor AMD GPU driver updates and apply them promptly. If using Polaris GPUs without PCIe atomics, consider disabling KFD or upgrading hardware if possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98178. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart