Junglewise Threat Intelligence

CVE-2026-80618: Linux kernel drm/amdkfd double-unpin underflow in memory free

CVE-2026-80618 · Severity: info · Published 2026-08-28

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's AMD GPU driver has a logic error in memory deallocation that can cause an underflow warning when freeing certain special memory buffers (DOORBELL and MMIO). When an application attempts to free GPU memory that is still in use, the kernel prematurely removes a reference to the buffer before checking if it can be safely freed, leading to an over-release of the buffer when it is finally cleaned up during process shutdown. This can cause kernel warnings and potentially instability.

Technical details

The vulnerability is a reference-counting error in the `amdgpu_amdkfd_gpuvm_free_memory_of_gpu()` function within the AMD GPU driver. The function unpins DOORBELL and MMIO remap buffer objects (BOs) before checking whether they are still mapped to GPU memory via the `mapped_to_gpu_memory` check. When a BO is still mapped, the function returns -EBUSY and leaves the BO alive, but it has already been unpinned. When the BO is later freed during process teardown, it is unpinned a second time, triggering a ttm_bo_unpin() underflow warning at the TTM (translation table management) layer. The fix reorders the unpin operation to occur only after confirming the BO will actually be freed (after the mapped_to_gpu_memory check), ensuring each BO is unpinned exactly once.

Affected products

  • Linux Linux Kernel Multiple (patched in linux-5.10.y, linux-5.15.y, linux-6.x.y and others)

Timeline

  • 2026-08-28: disclosed: Advisory published on NVD
  • 2026-06-04: patched: Fix committed upstream by Yunxiang Li
  • 2026-07-24: other: Fix cherry-picked into stable kernel branches

References

Related threats