drm/amdgpu/gfx6: Use PFP on the compute queues too

Summary

CVECVE-2026-90286
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-09-17 17:17:25 UTC
Updated2026-09-18 18:17:51 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/gfx6: Use PFP on the compute queues too On GFX6, the compute rings use the same CP path as the graphics ring. The only difference is that they don't support draw commands. (As opposed to GFX7 and newer which have a separate command parser that is called MEC for compute queues.) This means that we have to take into consideration that the PFP also exists on compute queues on GFX6: Use PFP for register writes on both graphics and compute queues. In the pipeline sync, use the PFP to wait for the previous fence (and not the ME) to prevent the PFP from starting to execute the next submission while the ME is still in the previous submission. After a VM flush, emit PFP_SYNC_ME on compute queues as well.

Risk And Classification

Primary CVSS: v3.1 8.8 HIGH from 416baaa9-dc9f-4396-8d5f-8c081fb06d67

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

EPSS: 0.001640000 probability, percentile 0.060210000 (date 2026-09-21)


VersionSourceTypeScoreSeverityVector
3.1416baaa9-dc9f-4396-8d5f-8c081fb06d67Secondary8.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
3.1CNADECLARED8.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CVSS v3.1 Breakdown

Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 2cd46ad22383ab8372b86cdb5257589496099412 f37211b9c01433f0bbb4709d25df7a0257cf915b git Not specified
CNA Linux Linux affected 2cd46ad22383ab8372b86cdb5257589496099412 2aa869c6b23e0b1b7f39f762618852811d75deb9 git Not specified
CNA Linux Linux affected 2cd46ad22383ab8372b86cdb5257589496099412 fbabc39b4f0fc771b00525ffd448be6a84355048 git Not specified
CNA Linux Linux affected 2cd46ad22383ab8372b86cdb5257589496099412 b5d1d3e4519dc8f1b55d6b236848bed67b11a2e8 git Not specified
CNA Linux Linux affected 2cd46ad22383ab8372b86cdb5257589496099412 e1d3018e3621c90cec070b6915836ae129656663 git Not specified
CNA Linux Linux affected 2cd46ad22383ab8372b86cdb5257589496099412 8d752f1bb73fabe5a425acbf5c767c0fe68bf3c5 git Not specified
CNA Linux Linux affected 2cd46ad22383ab8372b86cdb5257589496099412 e399e9d7e291ccbeba6560fb8278c8d2aa744521 git Not specified
CNA Linux Linux affected 2cd46ad22383ab8372b86cdb5257589496099412 60f20946cd318518ddc2c0da12103c666b2b9564 git Not specified
CNA Linux Linux affected 4.9 Not specified
CNA Linux Linux unaffected 4.9 semver Not specified
CNA Linux Linux unaffected 5.10.270 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.221 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.188 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.157 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.110 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.52 6.18.* semver Not specified
CNA Linux Linux unaffected 7.2.6 7.2.* semver Not specified
CNA Linux Linux unaffected 7.3-rc1 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/e1d3018e3621c90cec070b6915836ae129656663 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/fbabc39b4f0fc771b00525ffd448be6a84355048 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/60f20946cd318518ddc2c0da12103c666b2b9564 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/2aa869c6b23e0b1b7f39f762618852811d75deb9 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/8d752f1bb73fabe5a425acbf5c767c0fe68bf3c5 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/e399e9d7e291ccbeba6560fb8278c8d2aa744521 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/b5d1d3e4519dc8f1b55d6b236848bed67b11a2e8 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/f37211b9c01433f0bbb4709d25df7a0257cf915b 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report