{"apiVersion":"1.0","identifier":"CVE-2026-72090","description":"In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Use caller client for debug BO sync amdxdna_drm_sync_bo_ioctl() looks up args->handle in the ioctl caller-s drm_file. For SYNC_DIRECT_FROM_DEVICE, it then calls amdxdna_hwctx_sync_debug_bo(), but passes abo->client. amdxdna_hwctx_sync_debug_bo() uses the passed client both as the handle namespace for debug_bo_hdl and as the owner of the hardware context xarray. Those must match the file that supplied args->handle. The BO-s stored client pointer is object state, not the ioctl context. Pass filp->driver_priv instead, matching the original handle lookup.","publishedAt":"2026-08-15T06:21:23","lastModifiedAt":"2026-08-17T06:18:07","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-72090","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","epssProbability":0.00154,"riskScore":0.79,"affectedProduct":"Linux kernel","affectedVersions":"unknown","vulnerabilityType":"Kernel","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-72090","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-72090","en":"https://www.redsauce.net/en/cves/CVE-2026-72090","fr":"https://www.redsauce.net/fr/cves/CVE-2026-72090","pt":"https://www.redsauce.net/pt/cves/CVE-2026-72090","de":"https://www.redsauce.net/de/cves/CVE-2026-72090","sk":"https://www.redsauce.net/sk/cves/CVE-2026-72090","el":"https://www.redsauce.net/el/cves/CVE-2026-72090"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-72090"}}