CVE-2026-53374
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/07/2026
Last modified:
29/07/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
drm/amdgpu: zero-initialize GART table on allocation<br />
<br />
GART TLB is flushed after unmapping but not after mapping. Since<br />
amdgpu_bo_create_kernel() does not zero-initialize the buffer, when a<br />
single PTE is written the TLB may speculatively load other uninitialized<br />
entries from the same cacheline. Those garbage entries can appear valid,<br />
and a subsequent write to another PTE in the same cacheline may cause the<br />
GPU to use a stale garbage PTE from the TLB.<br />
<br />
Fix this by calling memset_io() to zero-initialize the GART table with<br />
gart_pte_flags immediately after allocation.<br />
<br />
Using AMDGPU_GEM_CREATE_VRAM_CLEARED, SDMA-based clear will not work<br />
since SDMA needs GART to be initialized to work.<br />
<br />
(cherry picked from commit d9af8263b82b6eaa60c5718e0c6631c5037e4b24)
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 4.2 (including) | 6.1.175 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.2 (including) | 6.6.140 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.12.90 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (including) | 6.18.32 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.19 (including) | 7.0.9 (excluding) |
| cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/40df11255d71b02e20e70579f1b12b687e396e26
- https://git.kernel.org/stable/c/791941be5da125d9a1b228582bfdc300c05d05b3
- https://git.kernel.org/stable/c/8ae8b9e74bab94aab1d79f1688129bcc61c8b29a
- https://git.kernel.org/stable/c/91fbb5e635c8fb1b49e15c19da06480089ef719f
- https://git.kernel.org/stable/c/b17175d0a375b3ed5e81597dac4983fdb46e478d
- https://git.kernel.org/stable/c/e6c2e6c2e1fa066968a16aca1cb66cd1bdde7741



