Use of uninitialized resource in Linux kernel - CVE-2026-89827

 

Use of uninitialized resource in Linux kernel - CVE-2026-89827

Published: September 17, 2026


Vulnerability identifier: #VU150456
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-89827
CWE-ID: CWE-908
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use of an uninitialized resource in the AMDGPU UVD decode ring fence driver when restoring the fence sequence during UVD resume on an SR-IOV virtual function. A local user can trigger UVD resume to cause a denial of service.


Affected software

Linux kernel

How to mitigate CVE-2026-89827

Install security update from vendor's repository.


External References

Related Security Bulletins