Description
In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu/mes: Fix hung_queue_db_array loop limit for multi-XCC

The loop iterated only AMDGPU_MAX_MES_PIPES times, leaving entries
uninitialized for multi-XCC GPUs. This causes null pointer dereferences
when accessing arrays indexed by XCC ID >= 2. Extend the loop to cover
all XCCs (AMDGPU_MAX_MES_PIPES * num_xcc), matching other per-XCC
arrays.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via kernel crash
Action: Immediate Patch
AI Analysis

Impact

The AMDGPU driver contains a loop that iterates only a fixed number of times (AMDGPU_MAX_MES_PIPES), which is insufficient for multi-XCC GPUs where the number of XCCs can be larger. When a job is queued for an XCC ID greater than or equal to 2, the driver indexes an array that, because of the loop limit, was never initialized. This results in a null pointer dereference inside the kernel, which will trigger a panic and reboot the system. The impact is a disruption of service and could be leveraged to crash systems that rely on high‑performance GPUs. The vulnerability is an example of CWE‑476, a null pointer dereference.

Affected Systems

All Linux kernel versions that include the buggy AMDGPU driver before the patch referenced in this advisory. Users of systems with multi‑XCC GPUs (i.e., GPUs supporting more than one XCC) are affected. Exact kernel release information is not provided, but any kernel containing the older loop implementation is vulnerable.

Risk and Exploitability

The EPSS score is below 1 percent, indicating a very low likelihood of exploitation in the wild. The vulnerability is not listed in CISA KEV. Because the defect occurs within the kernel driver, it requires privileged kernel execution context or direct interaction with the GPU driver to trigger. An attacker would need to supply workloads targeting an XCC ID beyond the loop boundary. Due to the kernel panic it can cause a denial of service, but there is no evidence of code execution or data exfiltration from the information given.

Generated by OpenCVE AI on September 19, 2026 at 07:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to the patched version that includes the commit which extends the loop to cover all XCCs (AMDGPU_MAX_MES_PIPES * num_xcc).
  • If an immediate kernel update is not possible, configure the system to limit the usage of multi‑XCC GPUs to a single XCC by adjusting driver or firmware settings, thus avoiding indices beyond the loop limit.
  • After applying the patch or configuration changes, monitor system logs for any remaining GPU‑related crashes and verify that the driver reports a healthy state.

Generated by OpenCVE AI on September 19, 2026 at 07:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/mes: Fix hung_queue_db_array loop limit for multi-XCC The loop iterated only AMDGPU_MAX_MES_PIPES times, leaving entries uninitialized for multi-XCC GPUs. This causes null pointer dereferences when accessing arrays indexed by XCC ID >= 2. Extend the loop to cover all XCCs (AMDGPU_MAX_MES_PIPES * num_xcc), matching other per-XCC arrays.
Title drm/amdgpu/mes: Fix hung_queue_db_array loop limit for multi-XCC
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:39.448Z

Reserved: 2026-09-17T16:02:15.088Z

Link: CVE-2026-93139

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:08.863

Modified: 2026-09-17T17:18:08.863

Link: CVE-2026-93139

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T19:00:13Z

Weaknesses

No weakness.