Executive brief
The AMD GPU driver in the Linux kernel contained overly aggressive error handling code that would crash the entire system whenever certain memory alignment checks failed during GPU command submission. An attacker with sufficient privileges to trigger these rare alignment violations could cause a complete system crash, disrupting services and availability.
Technical details
This issue involves the replacement of BUG_ON() assertions with WARN_ON() assertions in the AMD GPU (GFX12) driver component (drivers/gpu/drm/amd/amdgpu/gfx_v12_0.c). BUG_ON() unconditionally crashes the kernel when a condition is violated, whereas WARN_ON() logs a warning but allows execution to continue. The vulnerable code checked memory alignment in multiple GPU ring buffer operations (fence emission, indirect buffer submission, and register memory operations). An attacker with the ability to submit malformed GPU commands or control GPU memory addresses could trigger these alignment violations, causing an immediate kernel panic and denial of service. The fix simply replaces the fatal assertions with non-fatal warnings, allowing the driver to continue operation even when alignment violations occur.
Affected products
- Linux Linux kernel multiple (AMD GPU driver GFX12 component)
Timeline
- 2026-08-10: disclosed
- 2026-08-03: patched