{"api_version":"1","generated_at":"2026-10-03T06:30:48+00:00","cve":"CVE-2026-90286","urls":{"html":"https://cve.report/CVE-2026-90286","api":"https://cve.report/api/cve/CVE-2026-90286.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-90286","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-90286"},"summary":{"title":"drm/amdgpu/gfx6: Use PFP on the compute queues too","description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/gfx6: Use PFP on the compute queues too\n\nOn GFX6, the compute rings use the same CP path as\nthe graphics ring. The only difference is that they\ndon't support draw commands. (As opposed to GFX7 and\nnewer which have a separate command parser that is\ncalled MEC for compute queues.)\n\nThis means that we have to take into consideration\nthat the PFP also exists on compute queues on GFX6:\n\nUse PFP for register writes on both graphics and\ncompute queues.\n\nIn the pipeline sync, use the PFP to wait for the\nprevious fence (and not the ME) to prevent the PFP\nfrom starting to execute the next submission while\nthe ME is still in the previous submission.\n\nAfter a VM flush, emit PFP_SYNC_ME on compute\nqueues as well.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-17 17:17:25","updated_at":"2026-09-18 18:17:51"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"8.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"8.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","data":{"baseScore":8.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/e1d3018e3621c90cec070b6915836ae129656663","name":"https://git.kernel.org/stable/c/e1d3018e3621c90cec070b6915836ae129656663","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/fbabc39b4f0fc771b00525ffd448be6a84355048","name":"https://git.kernel.org/stable/c/fbabc39b4f0fc771b00525ffd448be6a84355048","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/60f20946cd318518ddc2c0da12103c666b2b9564","name":"https://git.kernel.org/stable/c/60f20946cd318518ddc2c0da12103c666b2b9564","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/2aa869c6b23e0b1b7f39f762618852811d75deb9","name":"https://git.kernel.org/stable/c/2aa869c6b23e0b1b7f39f762618852811d75deb9","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/8d752f1bb73fabe5a425acbf5c767c0fe68bf3c5","name":"https://git.kernel.org/stable/c/8d752f1bb73fabe5a425acbf5c767c0fe68bf3c5","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/e399e9d7e291ccbeba6560fb8278c8d2aa744521","name":"https://git.kernel.org/stable/c/e399e9d7e291ccbeba6560fb8278c8d2aa744521","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/b5d1d3e4519dc8f1b55d6b236848bed67b11a2e8","name":"https://git.kernel.org/stable/c/b5d1d3e4519dc8f1b55d6b236848bed67b11a2e8","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/f37211b9c01433f0bbb4709d25df7a0257cf915b","name":"https://git.kernel.org/stable/c/f37211b9c01433f0bbb4709d25df7a0257cf915b","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-90286","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-90286","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 2cd46ad22383ab8372b86cdb5257589496099412 f37211b9c01433f0bbb4709d25df7a0257cf915b git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 2cd46ad22383ab8372b86cdb5257589496099412 2aa869c6b23e0b1b7f39f762618852811d75deb9 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 2cd46ad22383ab8372b86cdb5257589496099412 fbabc39b4f0fc771b00525ffd448be6a84355048 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 2cd46ad22383ab8372b86cdb5257589496099412 b5d1d3e4519dc8f1b55d6b236848bed67b11a2e8 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 2cd46ad22383ab8372b86cdb5257589496099412 e1d3018e3621c90cec070b6915836ae129656663 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 2cd46ad22383ab8372b86cdb5257589496099412 8d752f1bb73fabe5a425acbf5c767c0fe68bf3c5 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 2cd46ad22383ab8372b86cdb5257589496099412 e399e9d7e291ccbeba6560fb8278c8d2aa744521 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 2cd46ad22383ab8372b86cdb5257589496099412 60f20946cd318518ddc2c0da12103c666b2b9564 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 4.9","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 4.9 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.10.270 5.10.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.15.221 5.15.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.1.188 6.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.6.157 6.6.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.110 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.52 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.6 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"90286","cve":"CVE-2026-90286","epss":"0.001640000","percentile":"0.060210000","score_date":"2026-09-21","updated_at":"2026-09-22 00:03:19"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/gpu/drm/amd/amdgpu/gfx_v6_0.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"f37211b9c01433f0bbb4709d25df7a0257cf915b","status":"affected","version":"2cd46ad22383ab8372b86cdb5257589496099412","versionType":"git"},{"lessThan":"2aa869c6b23e0b1b7f39f762618852811d75deb9","status":"affected","version":"2cd46ad22383ab8372b86cdb5257589496099412","versionType":"git"},{"lessThan":"fbabc39b4f0fc771b00525ffd448be6a84355048","status":"affected","version":"2cd46ad22383ab8372b86cdb5257589496099412","versionType":"git"},{"lessThan":"b5d1d3e4519dc8f1b55d6b236848bed67b11a2e8","status":"affected","version":"2cd46ad22383ab8372b86cdb5257589496099412","versionType":"git"},{"lessThan":"e1d3018e3621c90cec070b6915836ae129656663","status":"affected","version":"2cd46ad22383ab8372b86cdb5257589496099412","versionType":"git"},{"lessThan":"8d752f1bb73fabe5a425acbf5c767c0fe68bf3c5","status":"affected","version":"2cd46ad22383ab8372b86cdb5257589496099412","versionType":"git"},{"lessThan":"e399e9d7e291ccbeba6560fb8278c8d2aa744521","status":"affected","version":"2cd46ad22383ab8372b86cdb5257589496099412","versionType":"git"},{"lessThan":"60f20946cd318518ddc2c0da12103c666b2b9564","status":"affected","version":"2cd46ad22383ab8372b86cdb5257589496099412","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/gpu/drm/amd/amdgpu/gfx_v6_0.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"4.9"},{"lessThan":"4.9","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"5.10.*","status":"unaffected","version":"5.10.270","versionType":"semver"},{"lessThanOrEqual":"5.15.*","status":"unaffected","version":"5.15.221","versionType":"semver"},{"lessThanOrEqual":"6.1.*","status":"unaffected","version":"6.1.188","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.157","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.110","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.52","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.6","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.10.270","versionStartIncluding":"4.9","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.15.221","versionStartIncluding":"4.9","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.1.188","versionStartIncluding":"4.9","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.157","versionStartIncluding":"4.9","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.110","versionStartIncluding":"4.9","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.52","versionStartIncluding":"4.9","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.6","versionStartIncluding":"4.9","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc1","versionStartIncluding":"4.9","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/gfx6: Use PFP on the compute queues too\n\nOn GFX6, the compute rings use the same CP path as\nthe graphics ring. The only difference is that they\ndon't support draw commands. (As opposed to GFX7 and\nnewer which have a separate command parser that is\ncalled MEC for compute queues.)\n\nThis means that we have to take into consideration\nthat the PFP also exists on compute queues on GFX6:\n\nUse PFP for register writes on both graphics and\ncompute queues.\n\nIn the pipeline sync, use the PFP to wait for the\nprevious fence (and not the ME) to prevent the PFP\nfrom starting to execute the next submission while\nthe ME is still in the previous submission.\n\nAfter a VM flush, emit PFP_SYNC_ME on compute\nqueues as well."}],"metrics":[{"cvssV3_1":{"baseScore":8.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:L - gfx_v6_0_ring_emit_pipeline_sync/emit_vm_flush/emit_wreg run from local DRM_IOCTL_AMDGPU_CS (amdgpu_cs_ioctl → amdgpu_cs_submit → amdgpu_job_run → amdgpu_ib_schedule → amdgpu_vm_flush) on GFX6 CP_RB1/RB2 compute rings; the trigger is the caller’s own CS IB on /dev/dri/renderD*, not a remote protocol message.\nAC:L - On GFX6, amdgpu_vm_check_compute_bug sets has_compute_vm_bug so every compute job with a VMID emits WAIT_REG_MEM via gfx_v6_0_ring_emit_pipeline_sync, and gmc_v6_0_emit_flush_gpu_tlb uses emit_wreg; usepfp was 0 so PFP never waits. The attacker submits sequential AMDGPU_HW_IP_COMPUTE IBs and PFP prefetching ahead of ME is normal hardware behavior, not a victim-timed race.\nPR:L - AMDGPU_CS is registered DRM_AUTH|DRM_RENDER_ALLOW in amdgpu_ioctls_kms; drm_ioctl_permit() does no capable() check for that path, so any unprivileged local user who can open the render node (typical render/video group) can create a ctx and submit compute IBs without init-namespace root.\nUI:N - The attacker opens their own /dev/dri/renderD* fd, issues DRM_IOCTL_AMDGPU_CTX/GEM_VA and DRM_IOCTL_AMDGPU_CS with ip_type=AMDGPU_HW_IP_COMPUTE, and trips gfx_v6_0_ring_emit_vm_flush themselves; no other user must mount, open, or interact with a GPU context.\nS:C - Without PFP_SYNC_ME after gfx_v6_0_ring_emit_vm_flush, and with WRITE_DATA of mmVM_CONTEXT*_PAGE_TABLE_BASE_ADDR/mmVM_INVALIDATE_REQUEST issued on ME, the PFP/CUs can DMA using stale GPUVM TLB entries after a VMID switch or unmap, crossing the GPUVM DMA isolation boundary that is supposed to confine each VMID to its current page tables.\nC:H - PACKET3_INDIRECT_BUFFER in gfx_v6_0_ring_emit_ib is fetched by PFP through GPUVM; if that fetch and the subsequent dispatch run before ME finishes gmc_v6_0_emit_flush_gpu_tlb, loads hit leftover translations to pages already reused by another process or the kernel, which is an arbitrary physical-memory read via GPU DMA.\nI:H - The same stale VM_CONTEXT PTEs let compute shaders and CP packets store through GPU VAs whose physical pages were remapped after GEM_VA unmap or VMID reuse, giving a GPU DMA write into recycled host pages and control-flow hijack via hostile packet bytes the PFP fetched from the wrong address.\nA:H - Invalid PFP reads of IB contents through a not-yet-invalidated TLB feed garbage into the SI CP (the commit’s stated failure mode), causing VM faults, compute-ring hangs on CP_RB1/RB2, and amdgpu GPU reset that takes down the shared GFX6 device."}]}],"providerMetadata":{"dateUpdated":"2026-09-18T17:54:16.537Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/f37211b9c01433f0bbb4709d25df7a0257cf915b"},{"url":"https://git.kernel.org/stable/c/2aa869c6b23e0b1b7f39f762618852811d75deb9"},{"url":"https://git.kernel.org/stable/c/fbabc39b4f0fc771b00525ffd448be6a84355048"},{"url":"https://git.kernel.org/stable/c/b5d1d3e4519dc8f1b55d6b236848bed67b11a2e8"},{"url":"https://git.kernel.org/stable/c/e1d3018e3621c90cec070b6915836ae129656663"},{"url":"https://git.kernel.org/stable/c/8d752f1bb73fabe5a425acbf5c767c0fe68bf3c5"},{"url":"https://git.kernel.org/stable/c/e399e9d7e291ccbeba6560fb8278c8d2aa744521"},{"url":"https://git.kernel.org/stable/c/60f20946cd318518ddc2c0da12103c666b2b9564"}],"title":"drm/amdgpu/gfx6: Use PFP on the compute queues too","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-90286","datePublished":"2026-09-17T16:08:15.335Z","dateReserved":"2026-09-11T19:38:34.797Z","dateUpdated":"2026-09-18T17:54:16.537Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-17 17:17:25","lastModifiedDate":"2026-09-18 18:17:51","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2,"impactScore":6}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"90286","Ordinal":"1","Title":"drm/amdgpu/gfx6: Use PFP on the compute queues too","CVE":"CVE-2026-90286","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"90286","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/gfx6: Use PFP on the compute queues too\n\nOn GFX6, the compute rings use the same CP path as\nthe graphics ring. The only difference is that they\ndon't support draw commands. (As opposed to GFX7 and\nnewer which have a separate command parser that is\ncalled MEC for compute queues.)\n\nThis means that we have to take into consideration\nthat the PFP also exists on compute queues on GFX6:\n\nUse PFP for register writes on both graphics and\ncompute queues.\n\nIn the pipeline sync, use the PFP to wait for the\nprevious fence (and not the ME) to prevent the PFP\nfrom starting to execute the next submission while\nthe ME is still in the previous submission.\n\nAfter a VM flush, emit PFP_SYNC_ME on compute\nqueues as well.","Type":"Description","Title":"drm/amdgpu/gfx6: Use PFP on the compute queues too"}]}}}