Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix the case that vm range is hole at svm_migrate_copy_to_vram When migration vm range is hole at cpu side(MIGRATE_PFN_MIGRATE set + MIGRATE_PFN_VALID unset) driver still allocates device pages. There is no dma map of src pages and migration. j is 0 and svm_migrate_copy_memory_gart() will return an uninitialized r. That can trigger out_free_vram_pages to drop all VRAM just set up. Initialize r and only call the last svm_migrate_copy_memory_gart if j > 0. Current code postponed the last page to the final copy. This patch flushes on the last page when reach to the end of current drm_buddy_block; avoids another svm_migrate_copy_memory_gart.
CVSS Score
HIGH
References
- https://git.kernel.org/stable/c/0a9a0e8a97da70a0336c9115178aaf1be29bcfb1
- https://git.kernel.org/stable/c/520e345ffe05aabef1db82beda4288afb1757ff2
- https://git.kernel.org/stable/c/ae806a95b28fcecb913430cfa45a252e91a945d6
FAQ
What is CVE-2026-89808?
CVE-2026-89808 is a vulnerability with a CVSS score of 7.8 (HIGH). In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix the case that vm range is hole at svm_migrate_copy_to_vram When migration vm range is hole at cpu side(MIGRATE_PFN...
How severe is CVE-2026-89808?
CVE-2026-89808 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-89808?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.