CVE-2026-46220

Source
https://cve.org/CVERecord?id=CVE-2026-46220
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-46220.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-46220
Downstream
Related
Published
2026-05-28T09:40:35.971Z
Modified
2026-07-21T09:53:03.220763682Z
Summary
drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission
Details

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu/sdma4: replace BUGON with WARNON in fence emission

sdmav40ringemitfence() contains two BUGON(addr & 0x3) assertions that verify fence writeback addresses are dword-aligned. These assertions can be reached from unprivileged userspace via crafted DRMIOCTLAMDGPU_CS submissions, causing a fatal kernel panic in a scheduler worker thread.

Replace both BUGON() calls with WARNON() to log the condition without crashing the kernel. A misaligned fence address at this point indicates a driver bug, but crashing the kernel is never the correct response when the assertion is reachable from userspace.

The CS IOCTL path is the correct place to filter invalid submissions; the ring emission callback is too late to do anything about it.

(cherry picked from commit b90250bd933afd1ba94d86d6b13821997b22b18e)

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46220.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
2130f89ced2cc0f5113bb427c1cbc7a4ca7729c7
Fixed
ecaa80318e900ca0c3f687742ede33b41cfd2f8e
Fixed
25e7d56a39657d56d1ea6d78992f7ed15dedb412
Fixed
d4c56932d29773e278be6a65a5384a36c95b89a4
Fixed
4f7ca00fa91daf0795ec6b3b130c5ebba1f155fe
Fixed
d331fb241a4602253976ddd65144a8ba2b05665d
Fixed
0b91ea46bb68abf98a082bf239092253bbd6aaa2
Fixed
a4fd82fb0757c180bf622907397c528b89a827b2
Fixed
78d2e624fa073c14970aa097adcf3ea31c157a66

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-46220.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.12.0
Fixed
5.10.258
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.209
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.175
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.140
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.90
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.32
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.9

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-46220.json"