{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90286","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.797Z","datePublished":"2026-09-17T16:08:15.335Z","dateUpdated":"2026-09-18T17:54:16.537Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:54:16.537Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/gfx6: Use PFP on the compute queues too\n\nOn GFX6, the compute rings use the same CP path as\nthe graphics ring. The only difference is that they\ndon't support draw commands. (As opposed to GFX7 and\nnewer which have a separate command parser that is\ncalled MEC for compute queues.)\n\nThis means that we have to take into consideration\nthat the PFP also exists on compute queues on GFX6:\n\nUse PFP for register writes on both graphics and\ncompute queues.\n\nIn the pipeline sync, use the PFP to wait for the\nprevious fence (and not the ME) to prevent the PFP\nfrom starting to execute the next submission while\nthe ME is still in the previous submission.\n\nAfter a VM flush, emit PFP_SYNC_ME on compute\nqueues as well."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - gfx_v6_0_ring_emit_pipeline_sync/emit_vm_flush/emit_wreg run from local DRM_IOCTL_AMDGPU_CS (amdgpu_cs_ioctl → amdgpu_cs_submit → amdgpu_job_run → amdgpu_ib_schedule → amdgpu_vm_flush) on GFX6 CP_RB1/RB2 compute rings; the trigger is the caller’s own CS IB on /dev/dri/renderD*, not a remote protocol message.\nAC:L - On GFX6, amdgpu_vm_check_compute_bug sets has_compute_vm_bug so every compute job with a VMID emits WAIT_REG_MEM via gfx_v6_0_ring_emit_pipeline_sync, and gmc_v6_0_emit_flush_gpu_tlb uses emit_wreg; usepfp was 0 so PFP never waits. The attacker submits sequential AMDGPU_HW_IP_COMPUTE IBs and PFP prefetching ahead of ME is normal hardware behavior, not a victim-timed race.\nPR:L - AMDGPU_CS is registered DRM_AUTH|DRM_RENDER_ALLOW in amdgpu_ioctls_kms; drm_ioctl_permit() does no capable() check for that path, so any unprivileged local user who can open the render node (typical render/video group) can create a ctx and submit compute IBs without init-namespace root.\nUI:N - The attacker opens their own /dev/dri/renderD* fd, issues DRM_IOCTL_AMDGPU_CTX/GEM_VA and DRM_IOCTL_AMDGPU_CS with ip_type=AMDGPU_HW_IP_COMPUTE, and trips gfx_v6_0_ring_emit_vm_flush themselves; no other user must mount, open, or interact with a GPU context.\nS:C - Without PFP_SYNC_ME after gfx_v6_0_ring_emit_vm_flush, and with WRITE_DATA of mmVM_CONTEXT*_PAGE_TABLE_BASE_ADDR/mmVM_INVALIDATE_REQUEST issued on ME, the PFP/CUs can DMA using stale GPUVM TLB entries after a VMID switch or unmap, crossing the GPUVM DMA isolation boundary that is supposed to confine each VMID to its current page tables.\nC:H - PACKET3_INDIRECT_BUFFER in gfx_v6_0_ring_emit_ib is fetched by PFP through GPUVM; if that fetch and the subsequent dispatch run before ME finishes gmc_v6_0_emit_flush_gpu_tlb, loads hit leftover translations to pages already reused by another process or the kernel, which is an arbitrary physical-memory read via GPU DMA.\nI:H - The same stale VM_CONTEXT PTEs let compute shaders and CP packets store through GPU VAs whose physical pages were remapped after GEM_VA unmap or VMID reuse, giving a GPU DMA write into recycled host pages and control-flow hijack via hostile packet bytes the PFP fetched from the wrong address.\nA:H - Invalid PFP reads of IB contents through a not-yet-invalidated TLB feed garbage into the SI CP (the commit’s stated failure mode), causing VM faults, compute-ring hangs on CP_RB1/RB2, and amdgpu GPU reset that takes down the shared GFX6 device."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/gpu/drm/amd/amdgpu/gfx_v6_0.c"],"versions":[{"version":"2cd46ad22383ab8372b86cdb5257589496099412","lessThan":"f37211b9c01433f0bbb4709d25df7a0257cf915b","status":"affected","versionType":"git"},{"version":"2cd46ad22383ab8372b86cdb5257589496099412","lessThan":"2aa869c6b23e0b1b7f39f762618852811d75deb9","status":"affected","versionType":"git"},{"version":"2cd46ad22383ab8372b86cdb5257589496099412","lessThan":"fbabc39b4f0fc771b00525ffd448be6a84355048","status":"affected","versionType":"git"},{"version":"2cd46ad22383ab8372b86cdb5257589496099412","lessThan":"b5d1d3e4519dc8f1b55d6b236848bed67b11a2e8","status":"affected","versionType":"git"},{"version":"2cd46ad22383ab8372b86cdb5257589496099412","lessThan":"e1d3018e3621c90cec070b6915836ae129656663","status":"affected","versionType":"git"},{"version":"2cd46ad22383ab8372b86cdb5257589496099412","lessThan":"8d752f1bb73fabe5a425acbf5c767c0fe68bf3c5","status":"affected","versionType":"git"},{"version":"2cd46ad22383ab8372b86cdb5257589496099412","lessThan":"e399e9d7e291ccbeba6560fb8278c8d2aa744521","status":"affected","versionType":"git"},{"version":"2cd46ad22383ab8372b86cdb5257589496099412","lessThan":"60f20946cd318518ddc2c0da12103c666b2b9564","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/gpu/drm/amd/amdgpu/gfx_v6_0.c"],"versions":[{"version":"4.9","status":"affected"},{"version":"0","lessThan":"4.9","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.9","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.9","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.9","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.9","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.9","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.9","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.9","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.9","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/f37211b9c01433f0bbb4709d25df7a0257cf915b"},{"url":"https://git.kernel.org/stable/c/2aa869c6b23e0b1b7f39f762618852811d75deb9"},{"url":"https://git.kernel.org/stable/c/fbabc39b4f0fc771b00525ffd448be6a84355048"},{"url":"https://git.kernel.org/stable/c/b5d1d3e4519dc8f1b55d6b236848bed67b11a2e8"},{"url":"https://git.kernel.org/stable/c/e1d3018e3621c90cec070b6915836ae129656663"},{"url":"https://git.kernel.org/stable/c/8d752f1bb73fabe5a425acbf5c767c0fe68bf3c5"},{"url":"https://git.kernel.org/stable/c/e399e9d7e291ccbeba6560fb8278c8d2aa744521"},{"url":"https://git.kernel.org/stable/c/60f20946cd318518ddc2c0da12103c666b2b9564"}],"title":"drm/amdgpu/gfx6: Use PFP on the compute queues too","x_generator":{"engine":"bippy-1.2.0"}}}}