CVE-2026-46220 Details
Description
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission sdma_v4_0_ring_emit_fence() contains two BUG_ON(addr & 0x3) assertions that verify fence writeback addresses are dword-aligned. These assertions can be reached from unprivileged userspace via crafted DRM_IOCTL_AMDGPU_CS submissions, causing a fatal kernel panic in a scheduler worker thread. Replace both BUG_ON() calls with WARN_ON() to log the condition without crashing the kernel. A misaligned fence address at this point indicates a driver bug, but crashing the kernel is never the correct response when the assertion is reachable from userspace. The CS IOCTL path is the correct place to filter invalid submissions; the ring emission callback is too late to do anything about it. (cherry picked from commit b90250bd933afd1ba94d86d6b13821997b22b18e)
A vulnerability in the Linux kernel's AMDGPU driver for SDMA version 4.0 allows unprivileged users to cause a fatal kernel panic. This issue arises from two BUG_ON assertions in the fence emission function, which verify that fence writeback addresses are properly aligned. These assertions can be triggered by crafted DRM_IOCTL_AMDGPU_CS submissions from userspace, leading to a crash in a scheduler worker thread. The vulnerability has been addressed by replacing the BUG_ON calls with WARN_ON, allowing the kernel to log the misalignment issue without crashing. The alignment check failure indicates a driver bug, but the previous response of terminating the kernel was inappropriate, especially when the assertion could be reached from userspace.
Users can update to the latest version of the Linux kernel where this vulnerability has been fixed. Instructions for downloading the patched kernel can be found on the official Linux kernel website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/0b91ea46bb68abf98a082bf239092253bbd6aaa2 | kernel.org | Patch |
| https://git.kernel.org/stable/c/25e7d56a39657d56d1ea6d78992f7ed15dedb412 | kernel.org | Patch |
| https://git.kernel.org/stable/c/4f7ca00fa91daf0795ec6b3b130c5ebba1f155fe | kernel.org | Patch |
| https://git.kernel.org/stable/c/78d2e624fa073c14970aa097adcf3ea31c157a66 | kernel.org | Patch |
| https://git.kernel.org/stable/c/a4fd82fb0757c180bf622907397c528b89a827b2 | kernel.org | Patch |
| https://git.kernel.org/stable/c/d331fb241a4602253976ddd65144a8ba2b05665d | kernel.org | Patch |
| https://git.kernel.org/stable/c/d4c56932d29773e278be6a65a5384a36c95b89a4 | kernel.org | Patch |
| https://git.kernel.org/stable/c/ecaa80318e900ca0c3f687742ede33b41cfd2f8e | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-617 | Reachable Assertion | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 4.12, < 5.10.258 >= 5.11, < 5.15.209 >= 5.16, < 6.1.175 >= 6.2, < 6.6.140 >= 6.7, < 6.12.90 >= 6.13, < 6.18.32 >= 6.19, < 7.0.9 7.1 rc1 7.1 rc2 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Jun 10, 2026 | Initial Analysis | [email protected] |
| Jun 1, 2026 | CVE Modified | kernel.org |
| May 28, 2026 | New CVE Received | kernel.org |