GPU VulnDB

Database/NVIDIA / GPU stack

Linux amdgpu: resume force-completes an uninitialized UVD ring on SR-IOV virtual functions

UnscoredCVE-2026-89827NVIDIA / GPU stackcurated

Impact

On AMD GPUs passed through as SR-IOV virtual functions, uvd_v7_0_sw_init() never initializes the UVD decode ring, but amdgpu_uvd_resume() force-completes that ring's fences anyway, touching a fence driver that was never set up. The practical effect is a kernel oops or memory corruption in the guest's GPU driver on a resume/reset path, which on a VF-backed GPU node means the accelerator - and often the guest - stops serving. On a multi-tenant host that hands out AMD VFs, a tenant VM that triggers a GPU reset can lose its device state and require host-side intervention to recover the function. The fix skips fence completion when the fence driver is not initialized; it is a crash/corruption bug, not a privilege escalation, and no CVSS score is published in the record.

Who can reach it

Local to a guest holding an AMD SR-IOV virtual function, or the host driver itself, on code paths that resume or reset the UVD block. No remote or unauthenticated path is described in the record.

What to do

Pick up the fix from the stable trees linked in the record and roll the patched kernel out to AMD GPU hosts and guests running SR-IOV VFs; this is a kernel change, so each node must be drained and rebooted. Hosts that do not expose AMD VFs are not on the affected path. No fixed distribution version is named in the record.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.