{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-68103","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-07-30T09:28:09.368Z","datePublished":"2026-08-10T11:58:19.317Z","dateUpdated":"2026-08-17T04:58:51.492Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-17T04:58:51.492Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: reject mapping a reserved doorbell to a new queue\n\nWhen creating an user-queue, the user space\nprovides a doorbell BO handle and an offset within\nthe bo to obtain a doorbell.\n\nHowever current implementation using xa_store_irq()\nto store a doorbell, which allows a later queue created\nwith the same BO and offset parameters to overwrite an\nexisting queue and doorbell mapping.\n\nThis can cause problems like misrouting fence IRQ\nprocessing to a wrong queue, and mislead the cleanup\nprocess of one queue erasing the mapping of another queue.\n\nThis commit fixes this issue by replacing xa_store_irq with\nxa_insert_irq, which rejects mapping a reserved\ndoorbell to a newly created queue\n\n(cherry picked from commit 6244eae22966350db52faf9c1369d3b2ffc5de4e)"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","baseScore":7.1,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The bug is reached only through the AMDGPU DRM_USERQ ioctl on a local render node (/dev/dri/renderD*); fence IRQ handling is driven by local GPU completion events, not remote network input.\nAC:L - An attacker can deterministically trigger the overwrite by issuing AMDGPU_USERQ_OP_CREATE with the same doorbell GEM handle and offset (same process) or by landing on the same global doorbell BAR index (shared-GPU hosts); no race or victim timing is required.\nPR:L - Exploitation requires only access to the AMDGPU render node granted to normal local users (e.g., render/video group on workstations, cloud GPU VMs, ROCm compute nodes); high-priority queue creation is optional and not needed for the attack.\nUI:N - The attacker triggers the flaw directly via ioctls; victims need only be running ordinary GPU compute/graphics workloads on the same device, with no additional user interaction.\nS:U - Impact is confined to kernel AMDGPU user-queue and fence state on the local GPU; it does not cross VM, IOMMU, or sandbox boundaries into another security authority.\nC:N - Misrouting fence IRQs corrupts queue-to-doorbell associations and synchronization but provides no kernel or victim memory read primitive; AMDGPU per-process VM isolation blocks direct disclosure of another tenant's GPU buffers.\nI:H - Silently overwriting the device-global doorbell xarray lets an attacker hijack another queue's fence IRQ handling and erase its mapping on teardown, corrupting kernel queue state and breaking GPU synchronization integrity for other workloads.\nA:H - Orphaned queues stop receiving fence IRQs, provoking hang detection and amdgpu_userq_mgr_reset_work paths that can force per-queue or full GPU recovery, denying GPU service to all users on shared AMD GPU systems."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/gpu/drm/amd/amdgpu/amdgpu_userq.c"],"versions":[{"version":"8949843762631d9d0fc526dfb61a272dca29fc6f","lessThan":"1050d258c7c56066d2dcaedf8d0ef66364062adc","status":"affected","versionType":"git"},{"version":"8949843762631d9d0fc526dfb61a272dca29fc6f","lessThan":"a609b6278bf3cde17eeee6620091465521e4b02c","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/gpu/drm/amd/amdgpu/amdgpu_userq.c"],"versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","status":"unaffected","versionType":"semver"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.16","versionEndExcluding":"7.1.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.16","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/1050d258c7c56066d2dcaedf8d0ef66364062adc"},{"url":"https://git.kernel.org/stable/c/a609b6278bf3cde17eeee6620091465521e4b02c"}],"title":"drm/amdgpu: reject mapping a reserved doorbell to a new queue","x_generator":{"engine":"bippy-1.2.0"}}}}