Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-53374

Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
19/07/2026
Última modificación:
29/07/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> drm/amdgpu: zero-initialize GART table on allocation<br /> <br /> GART TLB is flushed after unmapping but not after mapping. Since<br /> amdgpu_bo_create_kernel() does not zero-initialize the buffer, when a<br /> single PTE is written the TLB may speculatively load other uninitialized<br /> entries from the same cacheline. Those garbage entries can appear valid,<br /> and a subsequent write to another PTE in the same cacheline may cause the<br /> GPU to use a stale garbage PTE from the TLB.<br /> <br /> Fix this by calling memset_io() to zero-initialize the GART table with<br /> gart_pte_flags immediately after allocation.<br /> <br /> Using AMDGPU_GEM_CREATE_VRAM_CLEARED, SDMA-based clear will not work<br /> since SDMA needs GART to be initialized to work.<br /> <br /> (cherry picked from commit d9af8263b82b6eaa60c5718e0c6631c5037e4b24)

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.2 (incluyendo) 6.1.175 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.2 (incluyendo) 6.6.140 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (incluyendo) 6.12.90 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (incluyendo) 6.18.32 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.19 (incluyendo) 7.0.9 (excluyendo)
cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*