CVE-2026-98270

Source
https://cve.org/CVERecord?id=CVE-2026-98270
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98270.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98270
Downstream
Published
2026-10-06T08:45:32Z
Modified
2026-10-08T02:52:56Z
Summary
drm/amdgpu: check ras and obj before dereference
Details

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu: check ras and obj before dereference

nbio_v7_9_handle_ras_controller_intr_no_bifring() dereferences ras and obj without checking either for NULL. Both amdgpu_ras_get_context() and amdgpu_ras_find_obj() can return NULL, e.g. during the window between adev->nbio.ras being set (early in amdgpu_ras_init(), by design, to enable the fatal-error interrupt as soon as possible) and the PCIE_BIF ras object actually being created in RAS late_init. Any interrupt in that window crashes in hard-IRQ context.

This is analogous to commit d190b459b2a4 ("drm/amdgpu: the warning dereferencing obj for nbio_v7_4"), which fixed the same issue in the nbio_v7_4 handler.

Found by Linux Verification Center (linuxtesting.org) with SVACE.

(cherry picked from commit c7071767a50a32ed727cf800ac84372429e3b4b3)

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98270.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
7692e1ee2446fd1940b5caa6e09779504a58881a
Fixed
b7c7f07a40037514f8e890aa00f8d7b196d680cf
Fixed
fc5f845a291fc8175e6857cd6ad042818da192e8
Fixed
37583946d8751f8e285c467d770ac0b609b82a23
Fixed
315c22712715491f0dfafdaf2c2b437540e68702
Fixed
723d4dc628d764b19cf9efca14b82cca5ff020c9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98270.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.6.0
Fixed
6.6.158
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98270.json"