Back

HIGH

accel/amdxdna: Use caller client for debug BO sync

Published Aug 15, 2026

Description

amdxdna_drm_sync_bo_ioctl() looks up args->handle in the ioctl caller's drm_file. For SYNC_DIRECT_FROM_DEVICE, it then calls amdxdna_hwctx_sync_debug_bo(), but passes abo->client.

amdxdna_hwctx_sync_debug_bo() uses the passed client both as the handle namespace for debug_bo_hdl and as the owner of the hardware context xarray. Those must match the file that supplied args->handle. The BO's stored client pointer is object state, not the ioctl context.

Pass filp->driver_priv instead, matching the original handle lookup.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (8)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner Linux
Published Aug 15, 2026
Updated Aug 17, 2026
Reserved Aug 9, 2026

CISA Vulnrichment

No data

NVD

Status Received
Modified Aug 17, 2026

Red Hat

Severity Moderate
Public date Aug 15, 2026
Bugzilla 2516315

ENISA EUVD

Assigner Linux
Published Aug 15, 2026
Updated Aug 17, 2026

GitHub

No data