CVE-2026-89978

In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: return early from a zero-length flush SYNC_BO does not constrain its size, so a request for zero bytes reaches drm_clflush_virt_range(), which ends with an unconditional clflushopt(end - 1). For an empty range that is the byte before the mapping, and abo->mem.kva comes from vmap(), so the access lands in the guard page below the vmalloc area and faults: BUG: unable to handle page fault for address: ffffd16fbbc70fff #PF: supervisor read access in kernel mode Oops: Oops: 0000 [#1] SMP NOPTI CPU: 7 UID: 1000 Comm: sync_bo_probe RIP: 0010:drm_clflush_virt_range+0x3c/0x70 Call Trace: amdxdna_drm_sync_bo_ioctl+0x124/0x430 [amdxdna] drm_ioctl+0x301/0x4c0 __x64_sys_ioctl+0x115/0x2f0 do_syscall_64+0xa6/0x3d0 Any process that can open the render node can do this. Reproduced 3 of 3 times on a Strix Point NPU (1022:17f0), by calling SYNC_BO with size 0 on an AMDXDNA_BO_SHARE object. The import arm takes the same request but flushes the whole scatterlist, so it survives it. Nothing needs flushing for an empty range, so answer before choosing a path.

Package Linux Kernel
Published 2026-09-16
Last modified 2026-09-16
Patch available
Yes

Affected versions

Linux kernel versions 6.17 and later are affected. Fixed in 6.18.52, 7.2.5, 7.3-rc2 and their respective stable series.

Affected from
≥ 6.17
Fixed in
✓ 6.18.52 6.18.x ✓ 7.2.5 7.2.x ✓ 7.3-rc2

Frequently asked questions

  • What is CVE-2026-89978?

    CVE-2026-89978 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 6.17 onward and has been patched in 6.18.52, 7.2.5 and 7.3-rc2. CVE-2026-89978 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.

  • Is there a patch available for CVE-2026-89978?

    Yes. CVE-2026-89978 has been patched. Fixed versions include 6.18.52, 7.2.5 and 7.3-rc2. If you are running Linux kernel 6.17 or later up to the fix versions, apply the relevant patch for your kernel branch.

  • Is CVE-2026-89978 actively exploited?

    No. CVE-2026-89978 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.