Junglewise Threat Intelligence

CVE-2026-68114: Linux kernel amdgpu denial of service via unhandled alignment checks

CVE-2026-68114 · Severity: info · Published 2026-08-10

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's AMD GPU driver contained overly strict error handling that would crash the entire system when encountering alignment mismatches in GPU memory operations. This patch replaces fatal kernel crashes with warnings, allowing the system to continue operating even when these edge-case conditions occur. The vulnerability could be exploited to cause system unavailability through a denial-of-service attack.

Technical details

The vulnerability exists in the AMD GPU (amdgpu) driver's GFX 12.1 graphics pipeline implementation. Multiple code paths in the driver used BUG_ON() macros to validate memory address alignment (dword and qword boundaries), which unconditionally crash the kernel when triggered. The vulnerability class is improper error handling leading to denial of service. An attacker with the ability to submit GPU commands or influence GPU memory allocation patterns could craft inputs that violate these alignment checks, triggering a kernel panic. The fix replaces BUG_ON() with WARN_ON(), which logs a warning but allows execution to continue. No privilege escalation or data exposure occurs; the impact is limited to availability through system crash.

Affected products

  • Linux Linux kernel affected versions prior to 6.10+ with the patch applied

Timeline

  • 2026-08-10: disclosed
  • 2026-06-15: patched

References

Related threats