{"id":"CVE-2026-80728","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nRevert \"drm/amdgpu: fix aperture mapping leak\"\n\ndevres teardown is LIFO","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nRevert \"drm/amdgpu: fix aperture mapping leak\"\n\ndevres teardown is LIFO. The aperture devres node was registered after\nthe DRM device node, so devres_release_all() unma…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= 67bc3647e418e23dc0d17604bdba634a73de809f < 7380f1bfe9d7ed3a4ca9d99a5c4df840fff9af2a","Linux >= a343d028ad6c174da8dc6af560c51e6d140a6727 < 96d26143882f9cb47dcc1f3dd4e26d047e53ab9b","Linux >= 6405c4e75b3bcf0e72bd7a0ff5f1ed0c475e23aa < a2e326c52c4bcecc033cd3ca2733fdbe30fbf55d","Linux >= f5988b5c300a32ff751724ffd33d5a8d5873e4a7 < 496846a9411136eb9e86ad4f4e62d751bd1e1db5","Linux >= ea772a440d56b285f4d491affac50ecd41f6b402 < b96c529cd2551b78316a4afa3237b2ed96ba03c8","Linux >= 6.6.148 < 6.6.152","Linux >= 6.12.101 < 6.12.104","Linux >= 6.18.42 < 6.18.45","Linux >= 7.1.6 < 7.1.9"],"published":"2026-09-03","updated":"2026-09-29","sourceUpdated":"2026-09-29T13:17:52.727","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-80728","references":[{"url":"https://git.kernel.org/stable/c/496846a9411136eb9e86ad4f4e62d751bd1e1db5","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7380f1bfe9d7ed3a4ca9d99a5c4df840fff9af2a","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/96d26143882f9cb47dcc1f3dd4e26d047e53ab9b","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a2e326c52c4bcecc033cd3ca2733fdbe30fbf55d","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b96c529cd2551b78316a4afa3237b2ed96ba03c8","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-29T12:33:37.299Z","slug":"CVE-2026-80728","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nRevert \"drm/amdgpu: fix aperture mapping leak\"\n\ndevres teardown is LIFO. The aperture devres node was registered after\nthe DRM device node, so devres_release_all() unmaps the aperture before\nthe DRM device release callback fires amdgpu_device_fini_sw(). IP\nsw_fini callbacks (e.g. vcn_v4_0_sw_fini) write to fw_shared through a\npointer derived from aper_base_kaddr, causing a kernel page fault on\nprobe failure / rollback:\n\n  BUG: unable to handle page fault ... PMD 0\n  RIP: vcn_v4_0_sw_fini+0x7b/0x170 [amdgpu]\n  Call Trace:\n    amdgpu_device_fini_sw\n    amdgpu_driver_release_kms\n    devm_drm_dev_init_release\n    devres_release_all\n\nThis reverts commit d871e99879cb5fd1fa798b006b4888887e63a17a.\n\n(cherry picked from commit 336e0cd576817ac64a4b394ca2b3680029f3e37f)\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}