Linux kernel: AMDX DNA driver zerolength command chain flaw
CVE-2026-98145 Published on September 25, 2026
accel/amdxdna: reject a command chain that carries no commands
In the Linux kernel, the following vulnerability has been resolved:
accel/amdxdna: reject a command chain that carries no commands
A chain whose command_count is zero passes the payload length check,
because struct_size(payload, data, 0) is just the header. The fill loop
then does not run, so offset stays zero and the request is submitted with
a zero-length buffer.
On firmware without AIE2_NPU_COMMAND that ends at the opcode check, since
op is still ERT_INVALID_CMD and aie2_get_chain_msg_op() answers
MSG_OP_MAX_OPCODE. aie2_get_npu_chain_msg_op() answers
MSG_OP_CHAIN_EXEC_NPU whatever it is given, so there the submission
continues to drm_clflush_virt_range(cmd_buf, 0), which reads the byte
before the buffer and faults on the vmap guard page. EXEC_CMD is
reachable by any process that can open the render node.
Reject the request instead.
Products Associated with CVE-2026-98145
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 8ed8b02396172b137ca8c78c3cb999ddf4fb0bbf and below ed74e8d603df457bfcf16ed4f8f1660a1525759e is affected.
- Version 8ed8b02396172b137ca8c78c3cb999ddf4fb0bbf and below ef6d27af71e1dc43181ec797a6aaa77c27c36786 is affected.
- Version 7.1 is affected.
- Before 7.1 is unaffected.
- Version 7.2.7, <= 7.2.* is unaffected.
- Version 7.3-rc2, <= * is unaffected.