In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: reject user command submission without a command BO… (CVE-2026-72091)
A vulnerability in the Linux kernel's AMD XDNA accelerator driver allows a user with access to the accelerator device node to trigger a kernel NULL pointer dereference. This occurs when a user submits a command buffer handle with an invalid value (0) that is not properly checked, leading to a kernel oops and potential denial of service. The issue arises because the driver fails to reject invalid command buffer handles on the user path, allowing a NULL pointer to be dereferenced in the DRM scheduler worker thread.
AI Analysis
Technical Summary
The Linux kernel AMD XDNA accelerator driver (amdxdna) improperly handles user command submissions when the command buffer (BO) handle is AMDXDNA_INVALID_BO_HANDLE (0). The function amdxdna_drm_submit_execbuf() passes this invalid handle without a proper check if drv_cmd is NULL, skipping the retrieval of job->cmd_bo and leaving it NULL. This leads to a NULL pointer dereference in the drm_sched worker when aie2_sched_job_run() calls amdxdna_cmd_set_state(job->cmd_bo), ultimately causing a kernel oops. Legitimate internal driver commands use this invalid handle but always set drv_cmd, so the fix is to reject invalid handles on user submissions where drv_cmd is NULL. This vulnerability can be triggered by any process with access to the accel node on systems with a probed AMD NPU.
Potential Impact
A local user with access to the AMD XDNA accelerator device node can cause a kernel NULL pointer dereference, resulting in a kernel oops and denial of service. This disrupts normal kernel operation and may require a system reboot. There is no indication of privilege escalation or code execution from the provided data.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is applied, restrict access to the AMD XDNA accelerator device node to trusted users only to prevent exploitation. Monitor vendor channels for an official patch or update addressing this issue.
In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: reject user command submission without a command BO… (CVE-2026-72091)
Description
A vulnerability in the Linux kernel's AMD XDNA accelerator driver allows a user with access to the accelerator device node to trigger a kernel NULL pointer dereference. This occurs when a user submits a command buffer handle with an invalid value (0) that is not properly checked, leading to a kernel oops and potential denial of service. The issue arises because the driver fails to reject invalid command buffer handles on the user path, allowing a NULL pointer to be dereferenced in the DRM scheduler worker thread.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel AMD XDNA accelerator driver (amdxdna) improperly handles user command submissions when the command buffer (BO) handle is AMDXDNA_INVALID_BO_HANDLE (0). The function amdxdna_drm_submit_execbuf() passes this invalid handle without a proper check if drv_cmd is NULL, skipping the retrieval of job->cmd_bo and leaving it NULL. This leads to a NULL pointer dereference in the drm_sched worker when aie2_sched_job_run() calls amdxdna_cmd_set_state(job->cmd_bo), ultimately causing a kernel oops. Legitimate internal driver commands use this invalid handle but always set drv_cmd, so the fix is to reject invalid handles on user submissions where drv_cmd is NULL. This vulnerability can be triggered by any process with access to the accel node on systems with a probed AMD NPU.
Potential Impact
A local user with access to the AMD XDNA accelerator device node can cause a kernel NULL pointer dereference, resulting in a kernel oops and denial of service. This disrupts normal kernel operation and may require a system reboot. There is no indication of privilege escalation or code execution from the provided data.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is applied, restrict access to the AMD XDNA accelerator device node to trusted users only to prevent exploitation. Monitor vendor channels for an official patch or update addressing this issue.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-jvc7-qr5g-mx5f
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-72091"]
- Ecosystems
- []
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a808b77bf8831d539500d42
Added to database: 08/15/2026, 15:53:27 UTC
Last enriched: 08/15/2026, 17:02:18 UTC
Last updated: 08/15/2026, 17:02:18 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.