GPU VulnDB

Database/NVIDIA / GPU stack

Linux kernel amdgpu: register BAR mapping leaks on every driver unload or hot-unplug

UnscoredCVE-2026-98179NVIDIA / GPU stackcurated

Impact

amdgpu_pci_remove() calls drm_dev_unplug() before fini_sw(), so drm_dev_enter() is already false by the time the guarded iounmap() runs and the register BAR ioremap mapping is never released. The .remove path covers both PCIe hot-unplug and a plain rmmod, so one mapping leaks per unload. On AMD accelerator nodes where driver reload is part of routine maintenance - reset sequences, driver version swaps, SR-IOV teardown - kernel mappings accumulate until the node is rebooted. This is a resource leak, not memory corruption, and there is no attacker-controlled input: severity is low and the record carries no score or CWE.

Who can reach it

Local root, or anything in the host's control plane that unloads or rebinds the amdgpu module, plus PCIe hot-unplug events. No unprivileged tenant path and nothing remote.

What to do

Pick up a stable kernel containing the fix (commits linked in the record) and reboot the node at your next maintenance window. Until then, rebooting rather than repeatedly reloading amdgpu clears the accumulated mappings. No vendor advisory or fixed distribution version is present in the record.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.