๐Ÿ” CVE Alert

CVE-2026-89828

UNKNOWN 0.0

drm/amdgpu: Fix init ordering in amdgpu_vram_mgr_init()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix init ordering in amdgpu_vram_mgr_init() drmm_cgroup_register_region() is called before INIT_LIST_HEAD() and gpu_buddy_init() in amdgpu_vram_mgr_init(). If it fails, the function returns early and bypasses those initializations. Since adev->mman.initialized is set to true before amdgpu_vram_mgr_init() is called, a failure triggers amdgpu_ttm_fini(), which calls amdgpu_vram_mgr_fini(), which then: - Calls list_for_each_entry_safe() on reservations_pending and reserved_pages, whose list_head::next pointers are zero-initialized (NULL). The loop does not recognize them as empty and dereferences NULL. - Calls gpu_buddy_fini(), which iterates free_trees[] unconditionally via for_each_free_tree(). Since mm->free_trees is NULL (never allocated), this dereferences NULL. Both result in a kernel panic on the module load error path. Fix by moving drmm_cgroup_register_region() to after the list and buddy allocator are fully initialized, so the teardown path is safe to run.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
2b624a2c18656ea32e0849e7bc0018ba3c97ca64 < e184e46ca1ba652ab8053a10a51b39aad06d3f5c 2b624a2c18656ea32e0849e7bc0018ba3c97ca64 < 3e234c6face8651045f46895dfe9c086ea64f03b 2b624a2c18656ea32e0849e7bc0018ba3c97ca64 < e773798e14ac0aea54ca9676083b91f445e5bc59
Linux / Linux
6.14

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/e184e46ca1ba652ab8053a10a51b39aad06d3f5c git.kernel.org: https://git.kernel.org/stable/c/3e234c6face8651045f46895dfe9c086ea64f03b git.kernel.org: https://git.kernel.org/stable/c/e773798e14ac0aea54ca9676083b91f445e5bc59