Junglewise Threat Intelligence

CVE-2026-68102: Linux kernel AMD GPU aperture mapping memory leak

CVE-2026-68102 · Severity: info · Published 2026-08-10

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's AMD GPU driver (amdgpu) has a memory management bug where GPU video memory aperture mappings are not properly cleaned up during driver unload. This causes orphaned memory mappings to persist in the kernel's address translation cache, which prevents the driver from reloading successfully on hardware that reconfigures the memory type. The practical impact is that systems cannot reload or reinitialize the AMD GPU driver without a full system restart.

Technical details

The vulnerability is a resource management bug in the amdgpu driver's TTM (Translation Table Maps) initialization. The root cause is that amdgpu_pci_remove() calls drm_dev_unplug() before invoking driver finalization routines, causing drm_dev_enter() checks in amdgpu_ttm_fini() to always return false. This prevents the iounmap(aper_base_kaddr) call from executing, leaving orphaned entries in the x86 PAT (Page Attribute Table) interval tree. On driver reload, connected_to_cpu hardware attempts to remap the same address range with different memory attributes (WC vs. WB), causing an ioremap conflict and discovery failure. The fix switches to device-resource-managed mappings (devm_memremap and devm_ioremap_wc) that guarantee cleanup at device_del() time, independent of drm_dev_enter() state. No authentication or user interaction is required; the bug manifests during normal driver unload/reload cycles.

Affected products

  • Linux Linux kernel Multiple versions (affecting 4.x, 5.x, 6.x series based on stable tree)

Timeline

  • 2026-08-10: disclosed: CVE published on NVD
  • 2026-08-03: patched: Patch committed upstream and cherry-picked to stable branches
  • 2026-06-14: other: Original upstream commit date

References

Related threats