CVE-2026-53374 Details
Description
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: zero-initialize GART table on allocation GART TLB is flushed after unmapping but not after mapping. Since amdgpu_bo_create_kernel() does not zero-initialize the buffer, when a single PTE is written the TLB may speculatively load other uninitialized entries from the same cacheline. Those garbage entries can appear valid, and a subsequent write to another PTE in the same cacheline may cause the GPU to use a stale garbage PTE from the TLB. Fix this by calling memset_io() to zero-initialize the GART table with gart_pte_flags immediately after allocation. Using AMDGPU_GEM_CREATE_VRAM_CLEARED, SDMA-based clear will not work since SDMA needs GART to be initialized to work. (cherry picked from commit d9af8263b82b6eaa60c5718e0c6631c5037e4b24)
A vulnerability in the Linux kernel's AMDGPU driver related to the Graphics Address Remapping Table (GART) has been addressed. The issue arose because the GART Translation Lookaside Buffer (TLB) is flushed after unmapping but not after mapping. The function 'amdgpu_bo_create_kernel()' failed to zero-initialize the buffer, leading to a situation where writing a single Page Table Entry (PTE) could cause the TLB to speculatively load other uninitialized entries from the same cache line. These garbage entries could be misinterpreted as valid, and a subsequent write to another PTE in the same cache line might result in the GPU using a stale, invalid PTE from the TLB. This vulnerability affects several versions of the Linux kernel.
The vulnerability has been fixed by modifying the GART table allocation function to include a step that zero-initializes the GART table with the appropriate flags immediately after allocation. This ensures that all entries are cleared before they can be used, preventing the TLB from loading any uninitialized data.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/40df11255d71b02e20e70579f1b12b687e396e26 | kernel.org | Patch |
| https://git.kernel.org/stable/c/791941be5da125d9a1b228582bfdc300c05d05b3 | kernel.org | Patch |
| https://git.kernel.org/stable/c/8ae8b9e74bab94aab1d79f1688129bcc61c8b29a | kernel.org | Patch |
| https://git.kernel.org/stable/c/91fbb5e635c8fb1b49e15c19da06480089ef719f | kernel.org | Patch |
| https://git.kernel.org/stable/c/b17175d0a375b3ed5e81597dac4983fdb46e478d | kernel.org | Patch |
| https://git.kernel.org/stable/c/e6c2e6c2e1fa066968a16aca1cb66cd1bdde7741 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 4.2, < 6.1.175 >= 6.2, < 6.6.140 >= 6.7, < 6.12.90 >= 6.13, < 6.18.32 >= 6.19, < 7.0.9 7.1 rc1 7.1 rc2 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 29, 2026 | Initial Analysis | [email protected] |
| Jul 20, 2026 | CVE Modified | kernel.org |
| Jul 20, 2026 | CVE Modified | kernel.org |
| Jul 19, 2026 | New CVE Received | kernel.org |