« Volver al listado

CVE-2026-90286

Estado: RecibidaAlta (8.8)—

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu/gfx6: Use PFP on the compute queues too

On GFX6, the compute rings use the same CP path as the graphics ring. The only difference is that they don't support draw commands. (As opposed to GFX7 and newer which have a separate command parser that is called MEC for compute queues.)

This means that we have to take into consideration that the PFP also exists on compute queues on GFX6:

Use PFP for register writes on both graphics and compute queues.

In the pipeline sync, use the PFP to wait for the previous fence (and not the ME) to prevent the PFP from starting to execute the next submission while the ME is still in the previous submission.

Leer descripción completaMostrar menos

After a VM flush, emit PFP_SYNC_ME on compute queues as well.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad de kernel (AV:L/PR:L) que permite escalada de privilegios mediante el manejo incorrecto de sincronización en colas de compute GFX6, impactando disponibilidad y posible ejecución de código con contexto elevado.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90286",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 2
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "2cd46ad22383ab8372b86cdb5257589496099412",
              "lessThan": "f37211b9c01433f0bbb4709d25df7a0257cf915b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2cd46ad22383ab8372b86cdb5257589496099412",
              "lessThan": "2aa869c6b23e0b1b7f39f762618852811d75deb9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2cd46ad22383ab8372b86cdb5257589496099412",
              "lessThan": "fbabc39b4f0fc771b00525ffd448be6a84355048",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2cd46ad22383ab8372b86cdb5257589496099412",
              "lessThan": "b5d1d3e4519dc8f1b55d6b236848bed67b11a2e8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2cd46ad22383ab8372b86cdb5257589496099412",
              "lessThan": "e1d3018e3621c90cec070b6915836ae129656663",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2cd46ad22383ab8372b86cdb5257589496099412",
              "lessThan": "8d752f1bb73fabe5a425acbf5c767c0fe68bf3c5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2cd46ad22383ab8372b86cdb5257589496099412",
              "lessThan": "e399e9d7e291ccbeba6560fb8278c8d2aa744521",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2cd46ad22383ab8372b86cdb5257589496099412",
              "lessThan": "60f20946cd318518ddc2c0da12103c666b2b9564",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/gpu/drm/amd/amdgpu/gfx_v6_0.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.9"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.9",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.270",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.221",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.188",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/gpu/drm/amd/amdgpu/gfx_v6_0.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:25.500",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/2aa869c6b23e0b1b7f39f762618852811d75deb9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/60f20946cd318518ddc2c0da12103c666b2b9564",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8d752f1bb73fabe5a425acbf5c767c0fe68bf3c5",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b5d1d3e4519dc8f1b55d6b236848bed67b11a2e8",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e1d3018e3621c90cec070b6915836ae129656663",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e399e9d7e291ccbeba6560fb8278c8d2aa744521",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f37211b9c01433f0bbb4709d25df7a0257cf915b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/fbabc39b4f0fc771b00525ffd448be6a84355048",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/gfx6: Use PFP on the compute queues too\n\nOn GFX6, the compute rings use the same CP path as\nthe graphics ring. The only difference is that they\ndon't support draw commands. (As opposed to GFX7 and\nnewer which have a separate command parser that is\ncalled MEC for compute queues.)\n\nThis means that we have to take into consideration\nthat the PFP also exists on compute queues on GFX6:\n\nUse PFP for register writes on both graphics and\ncompute queues.\n\nIn the pipeline sync, use the PFP to wait for the\nprevious fence (and not the ME) to prevent the PFP\nfrom starting to execute the next submission while\nthe ME is still in the previous submission.\n\nAfter a VM flush, emit PFP_SYNC_ME on compute\nqueues as well."
    }
  ],
  "lastModified": "2026-09-18T18:17:51.573",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}