Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Use caller client for debug BO sync amdxdna_drm_sync_bo_ioctl() looks up args->handle in the ioctl caller's drm_file. For SYNC_DIRECT_FROM_DEVICE, it then calls amdxdna_hwctx_sync_debug_bo(), but passes abo->client. amdxdna_hwctx_sync_debug_bo() uses the passed client both as the handle namespace for debug_bo_hdl and as the owner of the hardware context xarray. Those must match the file that supplied args->handle. The BO's stored client pointer is object state, not the ioctl context. Pass filp->driver_priv instead, matching the original handle lookup.
CVSS Score
HIGH
References
- https://git.kernel.org/stable/c/216e43d93dd49ec253052741aa476e51a8c54cd8
- https://git.kernel.org/stable/c/7caf2a2351d4053075670ff3e26a6815da0a9e1e
FAQ
What is CVE-2026-72090?
CVE-2026-72090 is a vulnerability with a CVSS score of 7.8 (HIGH). In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Use caller client for debug BO sync amdxdna_drm_sync_bo_ioctl() looks up args->handle in the ioctl caller's drm_fil...
How severe is CVE-2026-72090?
CVE-2026-72090 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-72090?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.