CVE-2026-89807

Source
https://cve.org/CVERecord?id=CVE-2026-89807
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89807.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-89807
Downstream
Published
2026-09-16T10:30:40Z
Modified
2026-09-18T03:48:32Z
Summary
drm/amdkfd: guard against NULL restore_mqd in CRIU queue restore
Details

In the Linux kernel, the following vulnerability has been resolved:

drm/amdkfd: guard against NULL restore_mqd in CRIU queue restore

Both create_queue_cpsch() and create_queue_nocpsch() unconditionally call mqd_mgr->restore_mqd() when a CRIU restore is in progress (qd != NULL), with no NULL guard. On any system where restore_mqd is not implemented for the given queue type, a user holding CAP_CHECKPOINT_RESTORE can trigger a kernel NULL pointer dereference and panic the machine by issuing KFD_IOC_CRIU_OP_RESTORE with a crafted queue restore object. Note that checkpoint_mqd is likewise unimplemented on GFX12, so no legitimate CRIU image can reach this path — only a hand-crafted restore payload.

Add a NULL guard for restore_mqd immediately after mqd_mgr is resolved, unwinding via the existing error labels and returning -EOPNOTSUPP if the callback is not implemented. This mirrors the existing checkpoint_mqd guard in checkpoint_mqd().

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89807.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
48f0bdf4e38e42b8285622cfcfc7e6e490b1a719
Fixed
19c73848493ab58e39649700da6de11710a36de1
Fixed
ebffa44e7a21ead59ac4b4264e8fc2cbb44c4a21
Fixed
c643c229babe2e8efc5eefe60e19d44868a643ff
Fixed
6aa530642f95d5c48aa336416f94a35e7949b647

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89807.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.11.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.51
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89807.json"