PT-2026-93452 · Linux · Linux Kernel
CVE-2026-89811
·
Published
2026-09-16
·
Updated
2026-09-24
CVSS v3.1
8.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A race condition exists in the Micro Engine Scheduler (MES), which fails to perform heavy-weight Translation Lookaside Buffer (TLB) invalidation after unmapping queues. This allows in-flight Direct Memory Access (DMA) descriptors to access memory that has already been unmapped, resulting in page faults and GPU queue hangs during Shared Virtual Memory (SVM) page migration. The issue specifically affects gfx1151 (Strix Point) hardware when XNACK mode 1 is enabled, causing the GPU compute queue to hang while packets remain unconsumed. The flaw is linked to the
evict process queues cpsch() and suspend queues() functions.Recommendations
Update the Linux kernel to a version that includes the fix implementing
kfd flush tlb() calls after MES queue removal in the evict process queues cpsch() and suspend queues() functions.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel