CVE-2026-31566 Details
Description
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix fence put before wait in amdgpu_amdkfd_submit_ib amdgpu_amdkfd_submit_ib() submits a GPU job and gets a fence from amdgpu_ib_schedule(). This fence is used to wait for job completion. Currently, the code drops the fence reference using dma_fence_put() before calling dma_fence_wait(). If dma_fence_put() releases the last reference, the fence may be freed before dma_fence_wait() is called. This can lead to a use-after-free. Fix this by waiting on the fence first and releasing the reference only after dma_fence_wait() completes. Fixes the below: drivers/gpu/drm/amd/amdgpu/amdgpu_amdkfd.c:697 amdgpu_amdkfd_submit_ib() warn: passing freed memory 'f' (line 696) (cherry picked from commit 8b9e5259adc385b61a6590a13b82ae0ac2bd3482)
A use-after-free vulnerability has been identified in the Linux kernel's AMDGPU driver, specifically within the job submission function for the AMD KFD (Kernel Fusion Driver) interface. The issue arises because the function improperly manages fence references, which are crucial for synchronizing GPU job completion. The vulnerability occurs when the code releases the last reference of a fence before ensuring that the corresponding wait operation has completed. This mismanagement can lead to a situation where the fence is freed while it is still needed, causing a use-after-free condition.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been addressed. The specific commit that fixes this issue is available in the Linux kernel stable tree.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/138e42be35ff2ce6572ae744de851ea286cf3c69 | kernel.org | Patch |
| https://git.kernel.org/stable/c/39820864eacd886f1a6f817414fb8f9ea3e9a2b4 | kernel.org | Patch |
| https://git.kernel.org/stable/c/42d248726a0837640452b71c5a202ca3d35239ec | kernel.org | Patch |
| https://git.kernel.org/stable/c/7150850146ebfa4ca998f653f264b8df6f7f85be | kernel.org | Patch |
| https://git.kernel.org/stable/c/bc7760c107dc08ef3e231d72c492e67b0a86848b | kernel.org | Patch |
| https://git.kernel.org/stable/c/e23602eb0779760544314ed3905fa6a89a4e4070 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-416 | Use After Free | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 6.0.1, < 6.1.168 >= 6.2, < 6.6.131 >= 6.7, < 6.12.80 >= 6.13, < 6.18.21 >= 6.19, < 6.19.11 6.0 - 7.0 rc1 7.0 rc2 7.0 rc3 7.0 rc4 7.0 rc5 7.0 rc6 7.0 rc7 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Apr 27, 2026 | Initial Analysis | [email protected] |
| Apr 27, 2026 | CVE Modified | kernel.org |
| Apr 24, 2026 | New CVE Received | kernel.org |