Executive brief
A vulnerability in the Linux kernel's AMD XDNA accelerator driver could cause a system crash. The issue occurs when the system attempts to unbind a device from a memory structure that has already been deleted. This could lead to a denial-of-service condition where the operating system stops functioning unexpectedly.
Technical details
A use-after-free vulnerability exists in the Linux kernel's accel/amdxdna driver. The root cause is a failure to maintain a reference count on the 'mm' (memory management) structure during the lifecycle of Shared Virtual Addressing (SVA) operations. Specifically, 'iommu_sva_unbind_device()' may attempt to access 'iommu_mm' after the associated 'mm' structure has been freed, leading to a kernel crash. The fix involves implementing 'mmgrab()' and 'mmdrop()' to ensure the memory structure remains valid until the device is successfully unbound. This is a local vulnerability that can be triggered during specific device lifecycle events.
Affected products
- Linux Linux Kernel Versions including amdxdna driver prior to fix
Timeline
- 2026-05-27: disclosed
- 2026-05-27: advisory