In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/sdma4: replace BUGON with WARNON in fence emission
sdmav40ringemitfence() contains two BUGON(addr & 0x3) assertions that verify fence writeback addresses are dword-aligned. These assertions can be reached from unprivileged userspace via crafted DRMIOCTLAMDGPU_CS submissions, causing a fatal kernel panic in a scheduler worker thread.
Replace both BUGON() calls with WARNON() to log the condition without crashing the kernel. A misaligned fence address at this point indicates a driver bug, but crashing the kernel is never the correct response when the assertion is reachable from userspace.
The CS IOCTL path is the correct place to filter invalid submissions; the ring emission callback is too late to do anything about it.
(cherry picked from commit b90250bd933afd1ba94d86d6b13821997b22b18e)
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46220.json",
"cna_assigner": "Linux"
}