CVE-2026-68234
Last modified
CVE-2026-68234 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved amdgpu_bo_create_reserved() only allocates a new BO when *bo_ptr (struct amdgpu_bo **bo_ptr as input parameter) is NULL, it simply skips creation when *bo_ptr is non-NULL. But it unconditionally reserves, pins, gart allocates and maps the BO afterwards. When the same non-NULL BO pointer is passed in again, for example firmware buffers that live in adev and are re-loaded on every resume / cp_resume / start under AMDGPU_FW_LOAD_DIRECT, amdgpu_bo_pin() just increases pin_count unconditionally, however the matching teardown only unpins once, so pin_count never drops to zero, so TTM is not able to move, swap or evict a BO, causing BO leaks. This commit fixes this issue by only pinning the bo once at creation, and repeated calls no longer take additional pin references. (cherry picked from commit 3ddc0ae76202c447b6aec61e907b852bc94671cf).
Description
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved amdgpu_bo_create_reserved() only allocates a new BO when *bo_ptr (struct amdgpu_bo **bo_ptr as input parameter) is NULL, it simply skips creation when *bo_ptr is non-NULL. But it unconditionally reserves, pins, gart allocates and maps the BO afterwards. When the same non-NULL BO pointer is passed in again, for example firmware buffers that live in adev and are re-loaded on every resume / cp_resume / start under AMDGPU_FW_LOAD_DIRECT, amdgpu_bo_pin() just increases pin_count unconditionally, however the matching teardown only unpins once, so pin_count never drops to zero, so TTM is not able to move, swap or evict a BO, causing BO leaks. This commit fixes this issue by only pinning the bo once at creation, and repeated calls no longer take additional pin references. (cherry picked from commit 3ddc0ae76202c447b6aec61e907b852bc94671cf)
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < 51eeef1949c11d3dcb5f422a5d9b3f09ebe8a1bc; >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < 2f390b4c83011452753fd84972f657d2b00a952b; >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < ba7b6444097a73ccd3d3ac9e2be4ebb73d226460; >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < 9743f60013273987abf415dc47474683d22aaee9; >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < a2f895f3c852063258d62e9f74b081de07ca95df; < 6.6.148; < 6.12.101; < 6.18.42; < 7.1.6 |
| Linux | Linux | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-68234?
How severe is CVE-2026-68234?
How do I fix CVE-2026-68234?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-68229In the Linux kernel, the following vulnerability has been re…
- CVE-2026-6823HKUDS OpenHarness prior to PR #147 remediation contains an i…8.3
- CVE-2026-68230In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68231In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68232In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68233In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68235In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68236In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68237In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68238In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68239In the Linux kernel, the following vulnerability has been re…
- CVE-2026-6824A stored cross-site scripting (XSS) vulnerability exists in …8.4
Are you affected by CVE-2026-68234?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
