Junglewise Threat Intelligence

CVE-2026-68111: Linux kernel AMD GPU driver denial of service hardening

CVE-2026-68111 · Severity: info · Published 2026-08-10

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

This update improves the robustness of the AMD GPU driver (amdgpu) in the Linux kernel by replacing fatal error handlers with non-fatal warnings. Previously, certain alignment validation checks in GPU command processing would crash the entire system; now they log warnings instead. This prevents malformed GPU commands from crashing the kernel, improving system stability and availability.

Technical details

This is a kernel hardening patch to the AMD GPU (amdgpu) driver in drivers/gpu/drm/amd/amdgpu/gfx_v9_0.c. The change replaces five instances of BUG_ON() assertions with WARN_ON() in GPU ring management functions (gfx_v9_0_wait_reg_mem, gfx_v9_0_ring_emit_ib_gfx, gfx_v9_0_ring_emit_ib_compute, and gfx_v9_0_ring_emit_fence). These assertions check for proper memory address alignment (0x3 or 0x7 byte boundaries) during GPU command queue operations. BUG_ON() terminates the kernel; WARN_ON() logs a warning and continues. A local attacker or misconfigured GPU workload triggering these alignment checks would previously crash the system; after patching, the driver continues operation with reduced reliability, improving availability. The patch has been backported to multiple stable kernel branches.

Affected products

  • Linux Linux kernel multiple stable branches

Timeline

  • 2026-08-10: disclosed
  • 2026-08-03: patched

References

Related threats