← Back to search

CVE-2026-90286

8.8 HIGH

Published 2026-09-17 · Updated 2026-09-18

AI risk analysis

Summary
This vulnerability in the Linux kernel's AMD GPU driver allows unauthorized access to the compute queues, potentially leading to privilege escalation or data leakage.
Exploitability
Exploitation requires kernel-level access and specific knowledge of AMD GPU architecture. Precondition is the presence of an affected AMD GPU driver version on the system.
Blast radius
If exploited, this could lead to full system compromise, as it allows execution of arbitrary code with kernel privileges.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to the Linux kernel version 6.1.18 or later.
kernelamdprivilege-escalationgpu

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/gfx6: Use PFP on the compute queues too On GFX6, the compute rings use the same CP path as the graphics ring. The only difference is that they don't support draw commands. (As opposed to GFX7 and newer which have a separate command parser that is called MEC for compute queues.) This means that we have to take into consideration that the PFP also exists on compute queues on GFX6: Use PFP for register writes on both graphics and compute queues. In the pipeline sync, use the PFP to wait for the previous fence (and not the ME) to prevent the PFP from starting to execute the next submission while the ME is still in the previous submission. After a VM flush, emit PFP_SYNC_ME on compute queues as well.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.