Linux drm/amdgpu: BAR0 fallback read path narrowed to SR-IOV VFs only
Impact
The BAR0 fallback read path exists as a workaround for SR-IOV virtual functions, where the VRAM aperture is not available during early initialization. Upstream restricted it so it is only taken on SR-IOV VFs, where it is actually needed, instead of on bare-metal devices too. The record gives no attacker, no crash signature and no CVSS; what it changes is which register-access path amdgpu takes while bringing up a device, which matters most on hosts that pass AMD GPUs to guests via SR-IOV. Treat it as a correctness fix in the GPU init path, not as an exploitable flaw - the record does not support a stronger claim.
Who can reach it
Not established by the record. The affected code runs during driver initialization, before any tenant workload exists; no remote or local attacker path is described.
What to do
Fixed in stable; take the kernel carrying commit 5612934c255a / bd1f08246b8a (cherry-picked from d8a0affd207c). Kernel update plus a node reboot; nothing urgent here, roll it with your normal kernel currency cycle.
References
Related entries
- Linux drm/ttm: swapped-out resources stay in their bulk_move range, leaving a dangling cursor (use-after-free)CVE-2026-98166 · Linux kernel drm/ttm (bulk_move bookkeeping on buffer-object swapout)Unscored
- Linux drm/amdkfd: integer underflow in the EOP ring size log calculationCVE-2026-98176 · Linux kernel drm/amdkfd (EOP ring size field in cp_hqd_eop_control)Unscored
- Linux drm/amdgpu: NULL dereference during GPU reset when KFD init failed after probeCVE-2026-98178 · Linux kernel drm/amdgpu (amdgpu_amdkfd_clear_kfd_mapping on GPU reset)Unscored
- Linux kernel amdgpu: register BAR mapping leaks on every driver unload or hot-unplugCVE-2026-98179 · Linux kernel amdgpu (register BAR iounmap on device removal)Unscored
- amdgpu nbio_v7_9: NULL dereference in hard IRQ when a RAS interrupt arrives before RAS late_initCVE-2026-98270 · Linux kernel amdgpu nbio_v7_9 (RAS controller interrupt handler)Unscored
- GPU / accelerator firmware (VBIOS, GSP, NVSwitch): GPU-resident firmware sits below the host OS and is not coveredNCVD-0000-012-gpu-accelerator-firmware-vbios-g · GPU / accelerator firmware (VBIOS, GSP, NVSwitch)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.