Answer in brief
CVE-2026-80618 records a Unknown severity vulnerability in drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=d25e35bc26c3ca8cd728101545cfb3e86a5d7431 <461ae406ae12107ebb321cabe561434c27aaea58 || >=d25e35bc26c3ca8cd728101545cfb3e86a5d7431 <283e77af49fda96aaa57709fc5408b55ffec075e || >=d25e35bc26c3ca8cd728101545cfb3e86a5d7431 <c055a2088b719e9a4b580685e0ca97f9554a41a8 || >=d25e35bc26c3ca8cd728101545cfb3e86a5d7431 <0e27d92f69b8e4c750a4b181cc05a86b9338c4f5 || >=d25e35bc26c3ca8cd728101545cfb3e86a5d7431 <1d12ae8b079e173107abec0e5817332954c8e95f || >=d25e35bc26c3ca8cd728101545cfb3e86a5d7431 <3f0cc1735273a57c5116710cf0202e12152f59cc | 461ae406ae12107ebb321cabe561434c27aaea58, 283e77af49fda96aaa57709fc5408b55ffec075e, c055a2088b719e9a4b580685e0ca97f9554a41a8, 0e27d92f69b8e4c750a4b181cc05a86b9338c4f5, 1d12ae8b079e173107abec0e5817332954c8e95f, 3f0cc1735273a57c5116710cf0202e12152f59cc |
| Linux/Linuxgeneric | 5.17 | Not reported |
Published upstream
Aug 28, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 28, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 28, 2026
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free amdgpu_amdkfd_gpuvm_free_memory_of_gpu() unpinned DOORBELL and MMIO remap BOs (which are pinned at allocation time) before checking whether the BO is still mapped to the GPU. When the BO is still mapped, the function returns -EBUSY and leaves the BO alive, but it has already been unpinned. The BO is then unpinned again when it is finally freed during process teardown, triggering a ttm_bo_unpin() underflow warning: WARNING: CPU: 18 PID: 15066 at ttm/ttm_bo.c:650 amdttm_bo_unpin+0x6d/0x80 [amdttm] Workqueue: kfd_process_wq kfd_process_wq_release [amdgpu] RIP: 0010:amdttm_bo_unpin+0x6d/0x80 [amdttm] Call Trace: amdgpu_bo_unpin+0x1a/0x90 [amdgpu] amdgpu_amdkfd_gpuvm_unpin_bo+0x31/0xb0 [amdgpu] amdgpu_amdkfd_gpuvm_free_memory_of_gpu+0x3bf/0x460 [amdgpu] kfd_process_free_outstanding_kfd_bos+0xd4/0x170 [amdgpu] kfd_process_wq_release+0x109/0x1b0 [amdgpu] process_one_work+0x1e2/0x3b0 worker_thread+0x50/0x3a0 kthread+0xdd/0x100 ret_from_fork+0x29/0x50 Move the unpin after the mapped_to_gpu_memory check so it only happens once we are committed to freeing the BO. (cherry picked from commit 927c5b2defb9b09856444d94bebfd056a002bd75)
Quoted source text, attributed separately from HOL analysis.