{"id":"CVE-2026-98178","title":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Skip KFD mapping clear before initialization\n\namdgpu_amdkfd_clear_kfd_mapping() assumes that a non-NULL kfd_dev\nhas a fully populated node array","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Skip KFD mapping clear before initialization\n\namdgpu_amdkfd_clear_kfd_mapping() assumes that a non-NULL kfd_dev\nhas a fully populated node array. This is no…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= 70cadefcc6160c575b04f763ada34c20e868d577 < 157d3f1db7e7e6f320daa221fae84a4c13555b6f","Linux >= 70cadefcc6160c575b04f763ada34c20e868d577 < 7f9caa70aef0950e06d395ca0035831214d88187","Linux 7.2"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T09:17:59.930","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-98178","references":[{"url":"https://git.kernel.org/stable/c/157d3f1db7e7e6f320daa221fae84a4c13555b6f","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7f9caa70aef0950e06d395ca0035831214d88187","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-06T08:50:17.452Z","slug":"CVE-2026-98178","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Skip KFD mapping clear before initialization\n\namdgpu_amdkfd_clear_kfd_mapping() assumes that a non-NULL kfd_dev\nhas a fully populated node array. This is not true when KFD device\ninitialization fails after probe.\n\nFor example, kgd2kfd_device_init() sets num_nodes before checking\nPCIe atomics support. On Polaris systems without the required atomics,\nit returns before allocating nodes[0], but the kfd_dev remains attached\nto the amdgpu device. A later GPU reset then dereferences nodes[0]->id.\n\nRequire the authoritative KFD initialization flag before walking the\nnode array, matching the existing KFD reset and teardown paths.\n\n(cherry picked from commit 4ac1835823c47903fbb278bbf474773c46f59edc)\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}