CVE-2026-43370

Source
https://cve.org/CVERecord?id=CVE-2026-43370
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43370.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-43370
Downstream
Related
Published
2026-05-08T14:21:21.926Z
Modified
2026-07-21T09:53:08.449966778Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
drm/amdgpu: Fix use-after-free race in VM acquire
Details

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu: Fix use-after-free race in VM acquire

Replace non-atomic vm->processinfo assignment with cmpxchg() to prevent race when parent/child processes sharing a drmfile both try to acquire the same VM after fork().

(cherry picked from commit c7c573275ec20db05be769288a3e3bb2250ec618)

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/43xxx/CVE-2026-43370.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ede0dd86f45adf2b7083bb161f6bc81da5fe2bad
Fixed
ae87aea330c24f462fc7058ed543ba8bc6798447
Fixed
46d309996bd9251792d7dafdbaf615cf202b4447
Fixed
e61e355cbe49e585097eee28c15b862bfb1c0668
Fixed
c658c1c85ec235b7ecfbf8dbfee385b1332088f4
Fixed
904025fa8bba1d028adade33346372b4ac1a9249
Fixed
7885eb335d8f9e9942925d57e300a85e3f82ded4
Fixed
94b7782d0c8024f5b88454241c8d4777076c3786
Fixed
2c1030f2e84885cc58bffef6af67d5b9d2e7098f

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43370.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.17.0
Fixed
5.10.253
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.203
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.167
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.130
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.78
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.19
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
6.19.9

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43370.json"