AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-72328

UNKNOWN · CVSS N/A

Source: NVD + CISA KEV + EPSS · Published 2026-08-15 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's AMD GPU driver, specifically within the handling of the amdxdna_umap object, which may lead to a use-after-free condition due to a race condition during concurrent operations. This could potentially allow an attacker to exploit the race condition to execute arbitrary code or cause system instability. Organizations using affected Linux distributions with AMD GPUs should prioritize this fix to mitigate potential security risks.

CVE
CVE-2026-72328
Severity
UNKNOWN
CVSS
N/A
EPSS
N/A
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Fix potential amdxdna_umap lifetime race amdxdna_umap_release() calls the blocking mmu_interval_notifier_remove() before removing the object from abo->mem.umap_list. If aie2_populate_range() runs concurrently, it may obtain a reference to an amdxdna_umap that is being released, leading to a potential use-after-free. Use kref_get_unless_zero() in aie2_populate_range() when acquiring a reference. If the reference count has already dropped to zero, release is in progress and the entry is skipped.