{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu: Fix init ordering in amdgpu_vram_mgr_init()  drmm_cgroup_register_region() is called before INIT_LIST_HEAD() and gpu_buddy_init() in amdgpu_vram_mgr_init(). If it fails, the function returns early and bypasses those initializations.  Since adev-\u003emman.initialized is set to true before amdgpu_vram_mgr_init() is called, a failure triggers amdgpu_ttm_fini(), which calls amdgpu_vram_mgr_fini(), which then:   - Calls list_for_each_entry_safe() on reservations_pending and    reserved_pages, whose list_head::next pointers are zero-initialized    (NULL). The loop does not recognize them as empty and dereferences NULL.   - Calls gpu_buddy_fini(), which iterates free_trees[] unconditionally    via for_each_free_tree(). Since mm-\u003efree_trees is NULL    (never allocated), this dereferences NULL.  Both result in a kernel panic on the module load error path.  Fix by moving drmm_cgroup_register_region() to after the list and buddy allocator are fully initialized, so the teardown path is safe to run.",
  "id": "DEBIAN-CVE-2026-89828",
  "modified": "2026-09-17T04:47:28.020984407Z",
  "published": "2026-09-16T11:16:49.493Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-89828"
    }
  ],
  "upstream": [
    "CVE-2026-89828"
  ]
}