Linux amdgpu: resume force-completes an uninitialized UVD ring on SR-IOV virtual functions
Impact
On AMD GPUs passed through as SR-IOV virtual functions, uvd_v7_0_sw_init() never initializes the UVD decode ring, but amdgpu_uvd_resume() force-completes that ring's fences anyway, touching a fence driver that was never set up. The practical effect is a kernel oops or memory corruption in the guest's GPU driver on a resume/reset path, which on a VF-backed GPU node means the accelerator - and often the guest - stops serving. On a multi-tenant host that hands out AMD VFs, a tenant VM that triggers a GPU reset can lose its device state and require host-side intervention to recover the function. The fix skips fence completion when the fence driver is not initialized; it is a crash/corruption bug, not a privilege escalation, and no CVSS score is published in the record.
Who can reach it
Local to a guest holding an AMD SR-IOV virtual function, or the host driver itself, on code paths that resume or reset the UVD block. No remote or unauthenticated path is described in the record.
What to do
Pick up the fix from the stable trees linked in the record and roll the patched kernel out to AMD GPU hosts and guests running SR-IOV VFs; this is a kernel change, so each node must be drained and rebooted. Hosts that do not expose AMD VFs are not on the affected path. No fixed distribution version is named in the record.
References
Related entries
- Linux kernel amdgpu: use of freed module text when RCU callbacks run after module unloadCVE-2026-93809 · Linux kernel amdgpu (missing rcu_barrier() on module unload)Unscored
- Linux kernel amdkfd: user-controlled metadata size lets any render-group user force a huge kernel allocationCVE-2026-93823 · Linux kernel amdkfd (AMDKFD_IOC_GET_DMABUF_INFO metadata buffer)Unscored
- Linux kernel amdgpu: unclamped write position in the vBIOS update sysfs attribute overflows the bufferCVE-2026-97425 · Linux kernel amdgpu (vBIOS update sysfs bin attribute)Unscored
- Linux kernel amdgpu powerplay: pp_table sysfs write memcpys up to PAGE_SIZE into a smaller heap bufferCVE-2026-97427 · Linux kernel amdgpu powerplay (pp_dpm_set_pp_table sysfs store)Unscored
- Linux kernel drm/amdgpu: unbounded VBIOS GPIO I2C entry count overruns adev->i2c_bus[]CVE-2026-97493 · Linux kernel amdgpu VBIOS GPIO I2C table parsing (drm/amdgpu)Unscored
- Linux amdgpu: PSP firmware image copied into the 1 MiB private buffer without a size checkCVE-2026-97494 · Linux kernel drm/amdgpu (PSP firmware private buffer, psp_copy_fw)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.