Linux kernel AMD XDNA driver: error path closes a live VMA and underflows its references
Impact
Two error paths in amdxdna_insert_pages() called vma->vm_ops->close(vma) before returning an error, dropping the shmem pages_pin_count and the GEM object reference that back the VMA while the mmap syscall has not even returned. The VMA stays alive, so kernel teardown calls close() a second time when the process unmaps the range, producing a reference count underflow and freeing the backing object early. The record does not establish controllable exploitation beyond that underflow, but a local user who can make the page insertion fail can reach it. Applies only to hosts with AMD XDNA NPU hardware and the amdxdna driver loaded.
Who can reach it
A local user or container with access to the amdxdna accel device node, mmapping a buffer object under conditions where page insertion hits one of the error paths. No elevated privileges beyond device access.
What to do
Update to a stable kernel with the deferred-fault fix and reboot. In the interim, gate access to the amdxdna accel device node with a device cgroup rule so only workloads that actually use the NPU can reach the path; unloaded drivers are not exposed.
References
Related entries
- Linux kernel amdgpu: duplicate FENCE chunks in one submission leak a buffer-object reference per submitCVE-2026-80539 · Linux kernel amdgpu (amdgpu_cs_pass1, duplicate AMDGPU_CHUNK_ID_FENCE chunks)Unscored
- Linux kernel amdgpu UVD: decode image size computed from width instead of pitchCVE-2026-80540 · Linux kernel amdgpu UVD (decode image minimum size validation, unbounded pitch)Unscored
- Linux kernel amdgpu: unvalidated GEM_CREATE domain combinations hit a BUG_ON and panic the nodeCVE-2026-80541 · Linux kernel amdgpu (amdgpu_gem_create_ioctl, GEM_CREATE domain combination validation)Unscored
- Linux kernel amdgpu display: NULL dereference when vblank is requested on a CRTC with no streamCVE-2026-80542 · Linux kernel amdgpu display core (amdgpu_dm_crtc_set_vblank, CRTC with no stream attached)Unscored
- Linux kernel amdgpu: user-supplied indirect buffer size is unbounded, corrupting ring packet fieldsCVE-2026-80576 · Linux kernel drm/amdgpu (command submission, amdgpu_cs_p2_ib IB size)Unscored
- Linux kernel amdkfd: double-unpin of doorbell/MMIO buffer objects corrupts TTM pin accountingCVE-2026-80618 · Linux kernel amdgpu/amdkfd (DOORBELL and MMIO remap BO free path)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.