CVE-2026-53374

Source
https://cve.org/CVERecord?id=CVE-2026-53374
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-53374.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-53374
Downstream
Published
2026-07-19T10:01:58.292Z
Modified
2026-07-21T03:46:30.007257845Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
drm/amdgpu: zero-initialize GART table on allocation
Details

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu: zero-initialize GART table on allocation

GART TLB is flushed after unmapping but not after mapping. Since amdgpubocreate_kernel() does not zero-initialize the buffer, when a single PTE is written the TLB may speculatively load other uninitialized entries from the same cacheline. Those garbage entries can appear valid, and a subsequent write to another PTE in the same cacheline may cause the GPU to use a stale garbage PTE from the TLB.

Fix this by calling memsetio() to zero-initialize the GART table with gartpte_flags immediately after allocation.

Using AMDGPUGEMCREATEVRAMCLEARED, SDMA-based clear will not work since SDMA needs GART to be initialized to work.

(cherry picked from commit d9af8263b82b6eaa60c5718e0c6631c5037e4b24)

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53374.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
d38ceaf99ed015f2a0b9af3499791bd3a3daae21
Fixed
40df11255d71b02e20e70579f1b12b687e396e26
Fixed
91fbb5e635c8fb1b49e15c19da06480089ef719f
Fixed
8ae8b9e74bab94aab1d79f1688129bcc61c8b29a
Fixed
b17175d0a375b3ed5e81597dac4983fdb46e478d
Fixed
791941be5da125d9a1b228582bfdc300c05d05b3
Fixed
e6c2e6c2e1fa066968a16aca1cb66cd1bdde7741

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-53374.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.2.0
Fixed
6.1.175
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.140
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.90
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.32
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.9

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-53374.json"