---
id: CVE-2026-89810
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  drm/amdkfd: Fix error path at svm_migrate_copy_to_ram

  If page migration from device to sys ram fails for some reasons driver needs
  release and unlock allocated system …
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  drm/amdkfd: Fix error path at svm_migrate_copy_to_ram

  If page migration from device to sys ram fails for some reasons driver needs
  release and unlock allocated system …
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <
    da87bcad1f781d822e7ced6d1de9dbc6d381c72e
  - >-
    Linux >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <
    a2035918a7a1d8fd3bb79d22e1e149294a5a8418
  - >-
    Linux >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <
    960c4a8069bfd352c48cc88592618f1ebe24c69e
  - Linux < 6.18.51
  - Linux < 7.2.5
  - Linux (all versions)
published: '2026-09-16'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T10:17:04.157'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89810'
references:
  - url: 'https://git.kernel.org/stable/c/960c4a8069bfd352c48cc88592618f1ebe24c69e'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/a2035918a7a1d8fd3bb79d22e1e149294a5a8418'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/da87bcad1f781d822e7ced6d1de9dbc6d381c72e'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-16T10:53:54.005Z'
epss: 0.00173
epssPercentile: 0.05977
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

drm/amdkfd: Fix error path at svm_migrate_copy_to_ram

If page migration from device to sys ram fails for some reasons driver needs
release and unlock allocated system pages. To do that driver should use page
physical address, or pfn, then get struct page*. Current driver uses dma
address(for adev) that is not correct with IOMMU enabled, or even in general.

The patch releases and unlocks allocated system pages based on where migration
failed by struct page* of sys ram pages. Also dma_unmap correspodent system
ram pages at error path.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
