{"id":"CVE-2026-89814","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-89814","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: clamp the isolation index for rings outside a partition\n\nadev->isolation[] has one slot per partition,…","details":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: clamp the isolation index for rings outside a partition\n\nadev->isolation[] has one slot per partition, but a ring that is not\nassigned to one keeps AMDGPU_XCP_NO_PARTITION, which is ~0, so indexing\nthe array with it is out of bounds. SDMA submissions hit this on both\nthe isolation enforcement and the VM flush path and trip UBSAN.\n\nFall back to the first slot the way the cleaner shader path already\ndoes, and stop taking the address before the ring type check that makes\nit relevant.","published":"2026-09-16T11:16:46.610","modified":"2026-09-16T11:16:46.610","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/0bfb938182d1313e5cac32ae38dbaaa4eabe4af4"},{"type":"WEB","url":"https://git.kernel.org/stable/c/964de255497ffd7cb8a86e405b8ac6d927e7e177"},{"type":"WEB","url":"https://git.kernel.org/stable/c/b30900566642ceb2c9e12b56c2afec28d0fd91a0"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-16T11:16:46.610"}}