{"api_version":"1","generated_at":"2026-10-10T00:39:27+00:00","cve":"CVE-2026-98144","urls":{"html":"https://cve.report/CVE-2026-98144","api":"https://cve.report/api/cve/CVE-2026-98144.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-98144","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-98144"},"summary":{"title":"accel/amdxdna: put the chained BO when its mapping fails","description":"In the Linux kernel, the following vulnerability has been resolved:\n\naccel/amdxdna: put the chained BO when its mapping fails\n\namdxdna_cmd_set_error() looks up the first BO of a command chain, which\ntakes a reference, and drops it at the end of the function. The mapping of\nthat BO is established in between, and the failure path returns without the\nput, so the reference is leaked.\n\nOrdinary use does not reach it. The chain has been submitted before any of\nthis runs, so aie2_cmdlist_fill_slot() has already called\namdxdna_cmd_get_op() on that BO and amdxdna_gem_vmap() has cached its\naddress. What makes it reachable is that the BO is resolved again by\nhandle here, and the handle is userspace's to recycle: closing it after\nsubmission and importing a dma-buf whose exporter implements no vmap onto\nthe same id leaves amdxdna_gem_get_obj() returning an object this cannot\nmap, since prime_import() types every import AMDXDNA_BO_SHARE.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-25 11:17:45","updated_at":"2026-09-30 14:10:59"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/eb90cb257e0792ac11f0347254bad3fc72417db6","name":"https://git.kernel.org/stable/c/eb90cb257e0792ac11f0347254bad3fc72417db6","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/7e33ba3a1d48c2d20ed270dec9d2d08332585c8e","name":"https://git.kernel.org/stable/c/7e33ba3a1d48c2d20ed270dec9d2d08332585c8e","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-98144","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98144","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected d76856beb4a4a6c42244054cd780c00f2d33de4e eb90cb257e0792ac11f0347254bad3fc72417db6 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected d76856beb4a4a6c42244054cd780c00f2d33de4e 7e33ba3a1d48c2d20ed270dec9d2d08332585c8e git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 7.1","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.7 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc2 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"98144","cve":"CVE-2026-98144","epss":"0.001450000","percentile":"0.031640000","score_date":"2026-09-27","updated_at":"2026-09-28 00:02:24"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/accel/amdxdna/amdxdna_ctx.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"eb90cb257e0792ac11f0347254bad3fc72417db6","status":"affected","version":"d76856beb4a4a6c42244054cd780c00f2d33de4e","versionType":"git"},{"lessThan":"7e33ba3a1d48c2d20ed270dec9d2d08332585c8e","status":"affected","version":"d76856beb4a4a6c42244054cd780c00f2d33de4e","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/accel/amdxdna/amdxdna_ctx.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"7.1"},{"lessThan":"7.1","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.7","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc2","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.7","versionStartIncluding":"7.1","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc2","versionStartIncluding":"7.1","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\naccel/amdxdna: put the chained BO when its mapping fails\n\namdxdna_cmd_set_error() looks up the first BO of a command chain, which\ntakes a reference, and drops it at the end of the function. The mapping of\nthat BO is established in between, and the failure path returns without the\nput, so the reference is leaked.\n\nOrdinary use does not reach it. The chain has been submitted before any of\nthis runs, so aie2_cmdlist_fill_slot() has already called\namdxdna_cmd_get_op() on that BO and amdxdna_gem_vmap() has cached its\naddress. What makes it reachable is that the BO is resolved again by\nhandle here, and the handle is userspace's to recycle: closing it after\nsubmission and importing a dma-buf whose exporter implements no vmap onto\nthe same id leaves amdxdna_gem_get_obj() returning an object this cannot\nmap, since prime_import() types every import AMDXDNA_BO_SHARE."}],"providerMetadata":{"dateUpdated":"2026-09-25T10:36:19.093Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/eb90cb257e0792ac11f0347254bad3fc72417db6"},{"url":"https://git.kernel.org/stable/c/7e33ba3a1d48c2d20ed270dec9d2d08332585c8e"}],"title":"accel/amdxdna: put the chained BO when its mapping fails","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-98144","datePublished":"2026-09-25T10:36:19.093Z","dateReserved":"2026-09-25T10:25:14.319Z","dateUpdated":"2026-09-25T10:36:19.093Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-25 11:17:45","lastModifiedDate":"2026-09-30 14:10:59","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"98144","Ordinal":"1","Title":"accel/amdxdna: put the chained BO when its mapping fails","CVE":"CVE-2026-98144","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"98144","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\naccel/amdxdna: put the chained BO when its mapping fails\n\namdxdna_cmd_set_error() looks up the first BO of a command chain, which\ntakes a reference, and drops it at the end of the function. The mapping of\nthat BO is established in between, and the failure path returns without the\nput, so the reference is leaked.\n\nOrdinary use does not reach it. The chain has been submitted before any of\nthis runs, so aie2_cmdlist_fill_slot() has already called\namdxdna_cmd_get_op() on that BO and amdxdna_gem_vmap() has cached its\naddress. What makes it reachable is that the BO is resolved again by\nhandle here, and the handle is userspace's to recycle: closing it after\nsubmission and importing a dma-buf whose exporter implements no vmap onto\nthe same id leaves amdxdna_gem_get_obj() returning an object this cannot\nmap, since prime_import() types every import AMDXDNA_BO_SHARE.","Type":"Description","Title":"accel/amdxdna: put the chained BO when its mapping fails"}]}}}