CVE-2026-98270
Received Received - Intake

Null Pointer Dereference in AMDGPU Linux Kernel Driver

Vulnerability report for CVE-2026-98270, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: check ras and obj before dereference nbio_v7_9_handle_ras_controller_intr_no_bifring() dereferences ras and obj without checking either for NULL. Both amdgpu_ras_get_context() and amdgpu_ras_find_obj() can return NULL, e.g. during the window between adev->nbio.ras being set (early in amdgpu_ras_init(), by design, to enable the fatal-error interrupt as soon as possible) and the PCIE_BIF ras object actually being created in RAS late_init. Any interrupt in that window crashes in hard-IRQ context. This is analogous to commit d190b459b2a4 ("drm/amdgpu: the warning dereferencing obj for nbio_v7_4"), which fixed the same issue in the nbio_v7_4 handler. Found by Linux Verification Center (linuxtesting.org) with SVACE. (cherry picked from commit c7071767a50a32ed727cf800ac84372429e3b4b3)

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
Linux Linux 7692e1ee2446fd1940b5caa6e09779504a58881a
Linux Linux 7692e1ee2446fd1940b5caa6e09779504a58881a
Linux Linux 7692e1ee2446fd1940b5caa6e09779504a58881a
Linux Linux 7692e1ee2446fd1940b5caa6e09779504a58881a
Linux Linux 7692e1ee2446fd1940b5caa6e09779504a58881a
Linux Linux 6.6

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a missing NULL check in the AMD GPU driver's error handling code. Specifically, the function nbio_v7_9_handle_ras_controller_intr_no_bifring() dereferences pointers ras and obj without verifying they are not NULL. These pointers can be NULL during a specific time window when the GPU's error interrupt is enabled before the required RAS object is fully initialized, leading to a crash in hard-IRQ context.

Detection Guidance

This vulnerability is specific to the Linux kernel's AMD GPU driver and requires kernel-level detection. Check kernel logs for crashes in hard-IRQ context related to amdgpu or nbio components. Look for NULL pointer dereference errors in drm/amdgpu logs.

Impact Analysis

If you use a system with an AMD GPU running a vulnerable Linux kernel version, this flaw could cause the system to crash unexpectedly during GPU-related operations. The crash occurs in a critical interrupt handler, making it difficult to recover without a reboot. This may lead to data loss or service disruption, especially in systems relying on GPU acceleration.

Mitigation Strategies

Update your Linux kernel to a patched version that includes the fix for this issue. Monitor kernel updates from your distribution and apply them promptly. If you cannot update immediately, consider disabling the AMD GPU driver or the affected functionality as a temporary workaround.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98270. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart