CVE-2026-98145

Source
https://cve.org/CVERecord?id=CVE-2026-98145
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98145.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98145
Downstream
Published
2026-09-25T10:36:19Z
Modified
2026-09-26T03:48:33Z
Summary
accel/amdxdna: reject a command chain that carries no commands
Details

In the Linux kernel, the following vulnerability has been resolved:

accel/amdxdna: reject a command chain that carries no commands

A chain whose command_count is zero passes the payload length check, because struct_size(payload, data, 0) is just the header. The fill loop then does not run, so offset stays zero and the request is submitted with a zero-length buffer.

On firmware without AIE2_NPU_COMMAND that ends at the opcode check, since op is still ERT_INVALID_CMD and aie2_get_chain_msg_op() answers MSG_OP_MAX_OPCODE. aie2_get_npu_chain_msg_op() answers MSG_OP_CHAIN_EXEC_NPU whatever it is given, so there the submission continues to drm_clflush_virt_range(cmd_buf, 0), which reads the byte before the buffer and faults on the vmap guard page. EXEC_CMD is reachable by any process that can open the render node.

Reject the request instead.

Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98145.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
8ed8b02396172b137ca8c78c3cb999ddf4fb0bbf
Fixed
ed74e8d603df457bfcf16ed4f8f1660a1525759e
Fixed
ef6d27af71e1dc43181ec797a6aaa77c27c36786

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98145.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
7.1.0
Fixed
7.2.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98145.json"