Executive brief
A vulnerability in the Linux kernel's AMD GPU driver could allow the system to use uninitialized memory when managing graphics resources. This occurs because certain memory tables used by the graphics card are not cleared upon creation, potentially leading to unpredictable system behavior or stability issues. In practice, this could result in system crashes or improper handling of graphics data.
Technical details
A vulnerability exists in the amdgpu driver within the Linux kernel where the GART table is not zero-initialized during allocation in amdgpu_gart_table_vram_alloc(). Because amdgpu_bo_create_kernel() does not clear the buffer, the Translation Lookaside Buffer (TLB) may speculatively load uninitialized Page Table Entries (PTEs) from the same cacheline when a single PTE is written. These uninitialized entries may appear valid, causing the GPU to use stale data. The fix involves calling memset_io() to ensure the GART table is properly initialized with gart_pte_flags immediately after allocation.
Affected products
- Linux Linux 6.1.175, 6.6.140, 6.12.90, 6.18.32, 7.0.9
Timeline
- 2026-07-19: disclosed
- 2026-07-19: advisory
References
- https://git.kernel.org/stable/c/40df11255d71b02e20e70579f1b12b687e396e26
- https://git.kernel.org/stable/c/791941be5da125d9a1b228582bfdc300c05d05b3
- https://git.kernel.org/stable/c/8ae8b9e74bab94aab1d79f1688129bcc61c8b29a
- https://git.kernel.org/stable/c/91fbb5e635c8fb1b49e15c19da06480089ef719f
- https://git.kernel.org/stable/c/b17175d0a375b3ed5e81597dac4983fdb46e478d
- https://git.kernel.org/stable/c/e6c2e6c2e1fa066968a16aca1cb66cd1bdde7741