Description
In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu/gfx6: Use PFP on the compute queues too

On GFX6, the compute rings use the same CP path as
the graphics ring. The only difference is that they
don't support draw commands. (As opposed to GFX7 and
newer which have a separate command parser that is
called MEC for compute queues.)

This means that we have to take into consideration
that the PFP also exists on compute queues on GFX6:

Use PFP for register writes on both graphics and
compute queues.

In the pipeline sync, use the PFP to wait for the
previous fence (and not the ME) to prevent the PFP
from starting to execute the next submission while
the ME is still in the previous submission.

After a VM flush, emit PFP_SYNC_ME on compute
queues as well.
Published: 2026-09-17
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

The vulnerability involves the AMDGPU driver for GFX6 GPUs in the Linux kernel, where compute queues previously did not use the PFP interface for register writes and pipeline synchronization. The lack of PFP handling caused the driver to wait for an incorrect fence, potentially allowing compute queue submissions to proceed prematurely. This mis‑synchronization could lead to inconsistent GPU state, unintended data exposure, or GPU stalls, effectively creating a denial of service path for workloads that rely on compute queues.

Affected Systems

Affected systems are Linux kernel installations that incorporate the AMDGPU driver for GFX6 GPUs, such as AMD Vega or older GPUs with GFX6 silicon. All kernel versions prior to the patch that exposed the compute queue PFP handling oversight are vulnerable, regardless of distribution or patch level.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity, while the EPSS score of less than 1% suggests a low probability of current exploitation. Because the issue resides in kernel driver code, an attacker would need to inject GPU commands that target compute queues on a GFX6 GPU – a scenario typically confined to systems with local or privileged access to the GPU. The vulnerability was not listed in the CISA KEV catalog, meaning no publicly known exploits are yet causing widespread attacks.

Generated by OpenCVE AI on September 20, 2026 at 01:00 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that contains the AMDGPU GFX6 compute queue PFP handling patch, such as kernels 6.x series that include the relevant commit.
  • If an immediate kernel upgrade is not feasible, restrict or disable the use of compute queues on GFX6 GPUs by configuring kernel module options or disabling the amdgpu driver for critical workloads.
  • Monitor system logs and GPU driver output for signs of GPU stalls or errors after the patch, and apply further updates as they become available.

Generated by OpenCVE AI on September 20, 2026 at 01:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/gfx6: Use PFP on the compute queues too On GFX6, the compute rings use the same CP path as the graphics ring. The only difference is that they don't support draw commands. (As opposed to GFX7 and newer which have a separate command parser that is called MEC for compute queues.) This means that we have to take into consideration that the PFP also exists on compute queues on GFX6: Use PFP for register writes on both graphics and compute queues. In the pipeline sync, use the PFP to wait for the previous fence (and not the ME) to prevent the PFP from starting to execute the next submission while the ME is still in the previous submission. After a VM flush, emit PFP_SYNC_ME on compute queues as well.
Title drm/amdgpu/gfx6: Use PFP on the compute queues too
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:54:16.537Z

Reserved: 2026-09-11T19:38:34.797Z

Link: CVE-2026-90286

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:25.500

Modified: 2026-09-18T18:17:51.573

Link: CVE-2026-90286

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T01:00:13Z

Weaknesses