GHSA-r66w-v4mr-3pxgHighCVSS 7.8
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix the case...
🔗 CVE IDs covered (1)
📋 Description
In the Linux kernel, the following vulnerability has been resolved:
drm/amdkfd: Fix the case that vm range is hole at svm_migrate_copy_to_vram
When migration vm range is hole at cpu side(MIGRATE_PFN_MIGRATE set + MIGRATE_PFN_VALID unset) driver still allocates device pages. There is no dma map of src pages and migration. j is 0 and svm_migrate_copy_memory_gart() will return an uninitialized r. That can trigger out_free_vram_pages to drop all VRAM just set up.
Initialize r and only call the last svm_migrate_copy_memory_gart if j > 0.
Current code postponed the last page to the final copy. This patch flushes on the last page when reach to the end of current drm_buddy_block; avoids another svm_migrate_copy_memory_gart.
🔗 References (5)
- https://nvd.nist.gov/vuln/detail/CVE-2026-89808
- https://git.kernel.org/stable/c/0a9a0e8a97da70a0336c9115178aaf1be29bcfb1
- https://git.kernel.org/stable/c/520e345ffe05aabef1db82beda4288afb1757ff2
- https://git.kernel.org/stable/c/ae806a95b28fcecb913430cfa45a252e91a945d6
- https://github.com/advisories/GHSA-r66w-v4mr-3pxg