Executive brief
A vulnerability in the Linux kernel's AMD graphics driver can cause systems to crash under specific hardware configurations. This issue occurs on systems equipped with two AMD graphics processors where only one supports certain power management features (ASPM). An exploit could lead to a complete system denial of service, impacting operational availability.
Technical details
The vulnerability stems from an erroneous re-application of a commit in the 'amdgpu' driver that incorrectly checked Active State Power Management (ASPM) status from the PCIe subsystem. This logic failed to account for multi-GPU systems where one GPU supports ASPM and another does not, leading to kernel panics or hard-to-debug system crashes. The issue was resolved by reverting the problematic code in 'amdgpu_pci_probe' within 'drivers/gpu/drm/amd/amdgpu/amdgpu_drv.c'. An attacker with local access could potentially trigger this condition to cause a denial of service. Patches have been backported to multiple stable kernel branches.
Affected products
- Linux Linux Kernel 5.15.54 to 5.16, 5.18 to 6.1.163, 6.2 to 6.6.124, 6.7 to 6.12.70, 6.13 to 6.18.10, 6.19-rc1 to 6.19-rc8
Timeline
- 2026-03-18: advisory: CVE published by kernel.org
- 2026-02-11: patched: Fixes merged into various stable kernel branches
References
- https://git.kernel.org/stable/c/243b467dea1735fed904c2e54d248a46fa417a2d
- https://git.kernel.org/stable/c/5b794951541e84d2968980a68dd1ac38420f75f3
- https://git.kernel.org/stable/c/5f645222eb30c91135119e12eccfd1b8ea88140e
- https://git.kernel.org/stable/c/d2bddc2da2b3ba5d738877c476bf97932dba32e8
- https://git.kernel.org/stable/c/f02c9052aaa031ef3c2285d86a155d4263180ddd