CVE-2026-90286

8.8

Linux · Kernel

A logic error in the Linux kernel amdgpu driver for GFX6 hardware allows for improper pipeline synchronization, potentially leading to privilege escalation or system instability.

Executive summary

A flaw in the Linux kernel amdgpu driver for GFX6 hardware, requiring local user privileges, can lead to full system compromise due to improper command processor synchronization.

Vulnerability

The vulnerability exists within the amdgpu driver when handling compute queues on GFX6 hardware, where the Pre-Fetch Parser (PFP) is not correctly utilized for register writes and pipeline synchronization. This allows a local authenticated user to trigger race conditions or command execution overlaps that can lead to unauthorized memory access or system crashes.

Business impact

The potential for privilege escalation and system compromise is significant, as an attacker with local access could leverage this flaw to gain elevated permissions or cause a denial of service. With a CVSS score of 8.8, this vulnerability is categorized as High, reflecting the severe impact on system integrity and availability. Such flaws in the kernel can facilitate lateral movement within a compromised environment or provide a path to bypass security boundaries.

Remediation

Immediate Action: Update the Linux kernel to version 5.10.270, 5.15.221, 6.1.188, 6.6.157, or later, depending on your current distribution branch.

Proactive Monitoring: Monitor system logs for kernel panics or unusual driver activity associated with the amdgpu module, which may indicate attempted exploitation.

Compensating Controls: Restrict access to the system to trusted users only, as the vulnerability requires local access to the affected hardware/driver interfaces.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the severity of potential kernel-level exploitation, administrators should prioritize applying the provided kernel patches as part of their next maintenance cycle. Ensure that all production Linux systems utilizing GFX6 series AMD graphics hardware are patched promptly to eliminate the risk of local privilege escalation.

More Linux CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. Analyst report written
  4. Published in the daily brief high section

Sources