---
id: CVE-2026-89978
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  accel/amdxdna: return early from a zero-length flush

  SYNC_BO does not constrain its size, so a request for zero bytes reaches
  drm_clflush_virt_range(), which ends with…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  accel/amdxdna: return early from a zero-length flush

  SYNC_BO does not constrain its size, so a request for zero bytes reaches
  drm_clflush_virt_range(), which ends with…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= e252e3f3488a49267e08ea7d972ac5ba3f2f1763 <
    45962da5821d0a691f638ccb13842889156d8969
  - >-
    Linux >= e252e3f3488a49267e08ea7d972ac5ba3f2f1763 <
    f00def884a831dc49eb659dac2dd09dbfd21e67f
  - >-
    Linux >= e252e3f3488a49267e08ea7d972ac5ba3f2f1763 <
    dc14753664240cedf669623b27ae9922b0618b25
  - Linux 6.17
published: '2026-09-16'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T11:17:08.667'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89978'
references:
  - url: 'https://git.kernel.org/stable/c/45962da5821d0a691f638ccb13842889156d8969'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/dc14753664240cedf669623b27ae9922b0618b25'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/f00def884a831dc49eb659dac2dd09dbfd21e67f'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-16T10:53:53.953Z'
epss: 0.00198
epssPercentile: 0.09868
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

accel/amdxdna: return early from a zero-length flush

SYNC_BO does not constrain its size, so a request for zero bytes reaches
drm_clflush_virt_range(), which ends with an unconditional
clflushopt(end - 1). For an empty range that is the byte before the
mapping, and abo->mem.kva comes from vmap(), so the access lands in the
guard page below the vmalloc area and faults:

  BUG: unable to handle page fault for address: ffffd16fbbc70fff
  #PF: supervisor read access in kernel mode
  Oops: Oops: 0000 [#1] SMP NOPTI
  CPU: 7 UID: 1000 Comm: sync_bo_probe
  RIP: 0010:drm_clflush_virt_range+0x3c/0x70
  Call Trace:
   amdxdna_drm_sync_bo_ioctl+0x124/0x430 [amdxdna]
   drm_ioctl+0x301/0x4c0
   __x64_sys_ioctl+0x115/0x2f0
   do_syscall_64+0xa6/0x3d0

Any process that can open the render node can do this. Reproduced 3 of 3
times on a Strix Point NPU (1022:17f0), by calling SYNC_BO with size 0 on
an AMDXDNA_BO_SHARE object. The import arm takes the same request but
flushes the whole scatterlist, so it survives it.

Nothing needs flushing for an empty range, so answer before choosing a
path.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
