{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89812","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.768Z","datePublished":"2026-09-16T10:30:45.246Z","dateUpdated":"2026-09-17T09:29:11.505Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-17T09:29:11.505Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: force complete the MES ring fences on reset\n\nThe MES scheduler ring has no drm scheduler (no_scheduler = true), so it is\nskipped by the force-completion loop in amdgpu_device_pre_asic_reset(). It uses\na polling fence whose hw value lives in wb (GTT) memory and survives a MODE1\nreset, while fence_drv.sync_seq keeps advancing for every packet.\n\nWhen the reset is triggered because MES itself stopped responding, the\ntimed-out packets advance sync_seq past the last hw fence value MES wrote.\nAfter resume the first MES submission polls forever on a seq that is never\nwritten back, failing the resume and wedging the box on a second reset:\n\n  amdgpu: MES ring buffer is full.\n  amdgpu: *ERROR* ring gfx_0.0.0 test failed (-110)\n  amdgpu: resume of IP block <gfx_v11_0> failed -110\n  amdgpu: GPU reset end with ret = -110\n\nForce complete the MES scheduler ring fences together with the scheduler rings\nso their hw fence is realigned to sync_seq.\n\nv2: cover all XCCs (one scheduler ring each), not just mes.ring[0]."}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/gpu/drm/amd/amdgpu/amdgpu_device.c"],"versions":[{"version":"34e087e8920e635c62e2ed6a758b0cd27f836d13","lessThan":"ebe7542553d008e2285e0fbba0c63f0295a7e694","status":"affected","versionType":"git"},{"version":"34e087e8920e635c62e2ed6a758b0cd27f836d13","lessThan":"48dc279c3010ac8f91b1845b2abb3a1e9943a0f5","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/gpu/drm/amd/amdgpu/amdgpu_device.c"],"versions":[{"version":"6.12","status":"affected"},{"version":"0","lessThan":"6.12","status":"unaffected","versionType":"semver"},{"version":"7.2.5","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.12","versionEndExcluding":"7.2.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.12","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/ebe7542553d008e2285e0fbba0c63f0295a7e694"},{"url":"https://git.kernel.org/stable/c/48dc279c3010ac8f91b1845b2abb3a1e9943a0f5"}],"title":"drm/amdgpu: force complete the MES ring fences on reset","x_generator":{"engine":"bippy-1.2.0"}}}}