SB20260812287 - Reachable assertion in Linux kernel amd amdgpu driver
Published: August 12, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Reachable assertion (CVE-ID: CVE-2026-68249)
CWE-ID: CWE-617 - Reachable Assertion
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper handling of a reachable assertion in the sdma_v5_0 fence emission logic when processing a crafted fence address. A local user can trigger the BUG_ON() condition to cause a denial of service.
The issue results in a kernel crash rather than continued execution.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0027cb19b0449ad6babedb1af285a713ab05c97f
- https://git.kernel.org/stable/c/28337e5d7df429bac7de64b17f1a595147778caa
- https://git.kernel.org/stable/c/9e98ed3113943257ad6e5c1e6beddbdb482a70ad
- https://git.kernel.org/stable/c/d20b5c139b2906bcd8ab4bfe5b8be500318161d1
- https://git.kernel.org/stable/c/f6212bc1bbd936fd9f7d77168b0c8b0019477b64