CVE-2026-89809

Source
https://cve.org/CVERecord?id=CVE-2026-89809
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-89809.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-89809
Downstream
Related
Published
2026-09-16T10:30:42Z
Modified
2026-09-25T18:27:28Z
Summary
drm/amdkfd: fix scope of mqd_mgr dereference in pqm_debugfs_mqds
Details

In the Linux kernel, the following vulnerability has been resolved:

drm/amdkfd: fix scope of mqd_mgr dereference in pqm_debugfs_mqds

Reading /sys/kernel/debug/kfd/mqds while a process holds an active KFD queue triggers a NULL pointer dereference because the for loop that calls mqd_mgr->debugfs_show_mqd() is incorrectly placed outside the if (pqn->q) block that initializes mqd_mgr.

The queue list can contain entries where pqn->q is NULL (kernel queues where only pqn->kq is valid). In the original code:

if (pqn->q) { ... mqd_mgr = q->device->dqm->mqd_mgrs[mqd_type]; size = mqd_mgr->mqd_stride(...); }

for (xcc = 0; xcc < num_xccs; xcc++) { // WRONG: outside if block mqd = q->mqd + size * xcc; r = mqd_mgr->debugfs_show_mqd(m, mqd); }

When iterating over a queue node where pqn->q is NULL:

  1. The if (pqn->q) block is skipped
  2. mqd_mgr remains uninitialized (NULL from declaration)
  3. The for loop executes anyway
  4. mqd_mgr->debugfs_show_mqd(m, mqd) dereferences NULL

The crash manifests as:

BUG: kernel NULL pointer dereference, address: 0000000000000000 #PF: supervisor instruction fetch in kernel mode RIP: 0010:0x0 Call Trace: pqm_debugfs_mqds+0x10c/0x1d0 [amdgpu] kfd_debugfs_mqds_by_process+0x9b/0x110 [amdgpu] seq_read_iter+0x132/0x4b0 ...

Fix by moving the for loop inside the if (pqn->q) block, so mqd_mgr and related variables are only used when properly initialized.

(cherry picked from commit 8bfe29d5c798940f797aa24135d2734c3ffce9de)

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89809.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
e1b73b64271d706079370b58b81292dafd373163
Fixed
58e866711b234571b0ce342c43d153a4786b32b8
Fixed
012a026bae0212952b423a842b7e2c0bf21f8e7a

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-89809.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
7.0.0
Fixed
7.2.5

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-89809.json"