Linux kernel AMD XDNA driver: unprivileged mmap plus MADV_DONTNEED trips a BUG_ON
Impact
amdxdna_insert_pages() sets VM_MIXEDMAP and clears VM_PFNMAP, which lets an unprivileged process that mmaps a non-imported GEM object clear the PTEs with madvise(MADV_DONTNEED). The next access faults into drm_gem_shmem_fault(), and vmf_insert_pfn_prot() hits BUG_ON((vma->vm_flags & VM_MIXEDMAP) && pfn_valid(pfn)) because the backing page is ordinary system memory - the record describes this as locally exploitable and predictable. That is an unprivileged local denial of service that panics the whole node, so on a shared machine one tenant holding the accelerator device node can take down every other workload on it. Exposure applies only to hosts with AMD XDNA NPU hardware and the amdxdna driver loaded.
Who can reach it
Any local user or container holding an open handle to the amdxdna accel device node. No elevated privileges are required beyond access to that device.
What to do
Update to a stable kernel with the fix and reboot the node. As an interim measure, restrict which containers get the amdxdna accel device node - a device cgroup rule removes the path entirely for workloads that do not need the NPU, and nodes without the driver loaded are not affected at all.
References
Related entries
- Linux kernel AMD XDNA driver: error path closes a live VMA and underflows its referencesCVE-2026-74721 · Linux kernel accel/amdxdna (amdxdna_insert_pages error paths call vm_ops->close)Unscored
- Linux kernel amdgpu: duplicate FENCE chunks in one submission leak a buffer-object reference per submitCVE-2026-80539 · Linux kernel amdgpu (amdgpu_cs_pass1, duplicate AMDGPU_CHUNK_ID_FENCE chunks)Unscored
- Linux kernel amdgpu UVD: decode image size computed from width instead of pitchCVE-2026-80540 · Linux kernel amdgpu UVD (decode image minimum size validation, unbounded pitch)Unscored
- Linux kernel amdgpu: unvalidated GEM_CREATE domain combinations hit a BUG_ON and panic the nodeCVE-2026-80541 · Linux kernel amdgpu (amdgpu_gem_create_ioctl, GEM_CREATE domain combination validation)Unscored
- Linux kernel amdgpu display: NULL dereference when vblank is requested on a CRTC with no streamCVE-2026-80542 · Linux kernel amdgpu display core (amdgpu_dm_crtc_set_vblank, CRTC with no stream attached)Unscored
- Linux kernel amdgpu: user-supplied indirect buffer size is unbounded, corrupting ring packet fieldsCVE-2026-80576 · Linux kernel drm/amdgpu (command submission, amdgpu_cs_p2_ib IB size)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.