accel/amdxdna: Remove __counted_by from struct amdxdna_cmd_chain
Summary
| CVE | CVE-2026-98146 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-25 11:17:46 UTC |
| Updated | 2026-09-30 14:10:59 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Remove __counted_by from struct amdxdna_cmd_chain struct amdxdna_cmd_chain contains a flexible array annotated with __counted_by(command_count). Since the structure is stored in shared AMDXDNA_BO_SHARE memory, userspace can modify command_count concurrently. If command_count is changed to zero, the bounds check generated from __counted_by may fail and trigger a kernel panic. Remove __counted_by to avoid relying on the userspace-controlled command_count for the flexible array bounds check. |
Risk And Classification
EPSS: 0.001540000 probability, percentile 0.038930000 (date 2026-09-27)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected aac243092b707bb3018e951d470cc1a9bcbaba6c 93fa3e925b15b0ded0a549fe7f12bfbb1c4e171a git | Not specified |
| CNA | Linux | Linux | affected aac243092b707bb3018e951d470cc1a9bcbaba6c 52f3e086760a9a3e02a46a10b57caffd73b1c204 git | Not specified |
| CNA | Linux | Linux | affected aac243092b707bb3018e951d470cc1a9bcbaba6c b3709d354545e70388177500761f92d906c4dfd6 git | Not specified |
| CNA | Linux | Linux | affected 6.14 | Not specified |
| CNA | Linux | Linux | unaffected 6.14 semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.53 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2.7 7.2.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.3-rc2 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/52f3e086760a9a3e02a46a10b57caffd73b1c204 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/93fa3e925b15b0ded0a549fe7f12bfbb1c4e171a | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/b3709d354545e70388177500761f92d906c4dfd6 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.