CVE-2026-46229 Details
Description
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure KFD VRAM allocations set AMDGPU_GEM_CREATE_VRAM_WIPE_ON_RELEASE but not AMDGPU_GEM_CREATE_VRAM_CLEARED, leaving freshly allocated VRAM with stale data from prior use observable by compute kernels. The GEM ioctl path already sets VRAM_CLEARED for all userspace allocations via amdgpu_gem_create_ioctl() and amdgpu_mode_dumb_create(). The KFD path was missing this flag, allowing stale page table remnants to leak into user buffers. This causes crashes in RCCL P2P transport where non-zero data in ptrExchange/head/tail fields corrupts the protocol handshake.
A vulnerability in the Linux kernel's handling of VRAM allocations for the Kernel Fusion Driver (KFD) can lead to the exposure of stale data. This issue arises because KFD VRAM allocations do not properly clear the memory before use, leaving remnants from previous allocations that can be observed by compute kernels. The problem has been addressed by modifying the allocation process to include a flag that ensures VRAM is cleared before being allocated to user buffers. This vulnerability was causing crashes in the RCCL P2P transport by corrupting protocol handshakes with residual data from prior VRAM usage.
The vulnerability has been fixed in the Linux kernel. Users should upgrade to the latest version where this issue has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/047d44d8d29a6a1a5757256837aa9dd78e3cd0b5 | kernel.org | Patch |
| https://git.kernel.org/stable/c/1db431380879fd9d28b763a88a0c0431be5be8df | kernel.org | Patch |
| https://git.kernel.org/stable/c/32b153658f017ad2f5bf8aab479e8d16ac95bc3a | kernel.org | Patch |
| https://git.kernel.org/stable/c/77d0b5d11387071770246fd0185a69fa28e8e109 | kernel.org | Patch |
| https://git.kernel.org/stable/c/ad52d61d82181dbdb7f05826de38352d5e550cc2 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 5.4, < 6.6.140 >= 6.7, < 6.12.90 >= 6.13, < 6.18.32 >= 6.19, < 7.0.9 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Jun 10, 2026 | Initial Analysis | [email protected] |
| May 28, 2026 | New CVE Received | kernel.org |