Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-68275

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
10/08/2026
Última modificación:
17/08/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> drm/amdgpu: check amdgpu_vm_bo_find() result in GET_MAPPING_INFO<br /> <br /> The AMDGPU_GEM_OP_GET_MAPPING_INFO path of amdgpu_gem_op_ioctl() looks<br /> up the bo_va for the buffer object in the caller&amp;#39;s VM via<br /> amdgpu_vm_bo_find(), but uses the returned pointer without checking it.<br /> <br /> amdgpu_vm_bo_find() returns NULL when the BO has no bo_va in that VM,<br /> which is the normal case for a BO that has never been mapped. The result<br /> is fed straight into amdgpu_vm_bo_va_for_each_valid_mapping(), which<br /> expands to list_for_each_entry(mapping, &amp;(bo_va)-&gt;valids, list) and<br /> dereferences bo_va, causing a NULL pointer dereference.<br /> <br /> This is reachable by any process able to issue the ioctl (render group)<br /> simply by requesting mapping info for an unmapped BO.<br /> <br /> Return -ENOENT when no bo_va is found, jumping to out_exec so the<br /> drm_exec context and GEM object reference are released.<br /> <br /> (cherry picked from commit 528b19377affc1cc7362a70a254c1dda793595f9)

Impacto