CVE-2026-68105
Status: ReceivedUnscored—
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: Fix kernel panic during driver load failure
Avoid kernel panic if MES init fails during driver load. The KIQ ring is falsely marked as ready as ASICs that use MES, KIQ is owned by MES.
(cherry picked from commit 4623b958dd6da0f4c3026afdf330626a09ecb0f0)
Technical details traces, logs and code from the original report
BUG: kernel NULL pointer dereference, address: 0000000000000000 RIP: 0010:gfx_v12_1_wait_reg_mem+0x5a/0x1f0 [amdgpu] Call Trace: gfx_v12_1_ring_emit_reg_write_reg_wait+0x1f/0x30 [amdgpu] amdgpu_gmc_fw_reg_write_reg_wait+0xb2/0x190 [amdgpu] amdgpu_gmc_flush_gpu_tlb+0x1cc/0x230 [amdgpu] amdgpu_gart_invalidate_tlb+0x81/0xa0 [amdgpu] amdgpu_gart_unbind+0x72/0x90 [amdgpu] amdgpu_ttm_backend_unbind+0xa4/0xb0 [amdgpu] amdgpu_ttm_tt_unpopulate+0x13/0xd0 [amdgpu] amdttm_tt_unpopulate+0x29/0x70 [amdttm] ttm_bo_put+0x1eb/0x360 [amdttm] amdgpu_bo_free_kernel+0xf9/0x1f0 [amdgpu] amdgpu_ih_ring_fini+0x5a/0x90 [amdgpu] amdgpu_irq_fini_hw+0x58/0x80 [amdgpu] amdgpu_device_fini_hw+0x4e0/0x5b0 [amdgpu] amdgpu_driver_load_kms+0x60/0xa0 [amdgpu] amdgpu_pci_probe+0x28e/0x6d0 [amdgpu] pci_device_probe+0x19f/0x220 really_probe+0x1ed/0x340 driver_probe_device+0x1e/0x80 __driver_attach+0xd3/0x1a0 bus_for_each_dev+0x68/0xa0 bus_add_driver+0x19f/0x270 driver_register+0x5d/0xf0 do_one_initcall+0xac/0x200 do_init_module+0x1ec/0x280 __se_sys_finit_module+0x2de/0x310 do_syscall_64+0x6a/0x250 entry_SYSCALL_64_after_hwframe+0x4b/0x53
CVSS
NVD hasn't assigned a CVSS score to this CVE (common since the April 2026 policy change).
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.15%
- Percentile among all scored CVEs: 4
- Score date: 10/5/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.
References
Raw JSON (NVD)
Show
{
"id": "CVE-2026-68105",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "52cb80c12e8a647aa9c903903d58916e6c1c4d38",
"lessThan": "5bc93f907bad7e076d814664dfab8fc230efca3d",
"versionType": "git"
},
{
"status": "affected",
"version": "52cb80c12e8a647aa9c903903d58916e6c1c4d38",
"lessThan": "a279bd143b3c184358b658e43a057e31ee8c4de5",
"versionType": "git"
}
],
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/gfx_v12_0.c",
"drivers/gpu/drm/amd/amdgpu/gfx_v12_1.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.11"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.11",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/gfx_v12_0.c",
"drivers/gpu/drm/amd/amdgpu/gfx_v12_1.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-10T13:19:55.223",
"references": [
{
"url": "https://git.kernel.org/stable/c/5bc93f907bad7e076d814664dfab8fc230efca3d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a279bd143b3c184358b658e43a057e31ee8c4de5",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Fix kernel panic during driver load failure\n\nAvoid kernel panic if MES init fails during driver load. The KIQ ring is\nfalsely marked as ready as ASICs that use MES, KIQ is owned by MES.\n\nBUG: kernel NULL pointer dereference, address: 0000000000000000\nRIP: 0010:gfx_v12_1_wait_reg_mem+0x5a/0x1f0 [amdgpu]\nCall Trace:\n gfx_v12_1_ring_emit_reg_write_reg_wait+0x1f/0x30 [amdgpu]\n amdgpu_gmc_fw_reg_write_reg_wait+0xb2/0x190 [amdgpu]\n amdgpu_gmc_flush_gpu_tlb+0x1cc/0x230 [amdgpu]\n amdgpu_gart_invalidate_tlb+0x81/0xa0 [amdgpu]\n amdgpu_gart_unbind+0x72/0x90 [amdgpu]\n amdgpu_ttm_backend_unbind+0xa4/0xb0 [amdgpu]\n amdgpu_ttm_tt_unpopulate+0x13/0xd0 [amdgpu]\n amdttm_tt_unpopulate+0x29/0x70 [amdttm]\n ttm_bo_put+0x1eb/0x360 [amdttm]\n amdgpu_bo_free_kernel+0xf9/0x1f0 [amdgpu]\n amdgpu_ih_ring_fini+0x5a/0x90 [amdgpu]\n amdgpu_irq_fini_hw+0x58/0x80 [amdgpu]\n amdgpu_device_fini_hw+0x4e0/0x5b0 [amdgpu]\n amdgpu_driver_load_kms+0x60/0xa0 [amdgpu]\n amdgpu_pci_probe+0x28e/0x6d0 [amdgpu]\n pci_device_probe+0x19f/0x220\n really_probe+0x1ed/0x340\n driver_probe_device+0x1e/0x80\n __driver_attach+0xd3/0x1a0\n bus_for_each_dev+0x68/0xa0\n bus_add_driver+0x19f/0x270\n driver_register+0x5d/0xf0\n do_one_initcall+0xac/0x200\n do_init_module+0x1ec/0x280\n __se_sys_finit_module+0x2de/0x310\n do_syscall_64+0x6a/0x250\n entry_SYSCALL_64_after_hwframe+0x4b/0x53\n\n(cherry picked from commit 4623b958dd6da0f4c3026afdf330626a09ecb0f0)"
}
],
"lastModified": "2026-08-17T05:18:09.887",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}