SB20260917151 - Improper Validation of Array Index in Linux kernel amd amdgpu driver



SB20260917151 - Improper Validation of Array Index in Linux kernel amd amdgpu driver

Published: September 17, 2026

Security Bulletin ID SB20260917151
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper Validation of Array Index (CVE-ID: CVE-2026-89814)

CWE-ID: CWE-129 - Improper Validation of Array Index

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to improper validation of an array index in the amdgpu isolation enforcement and VM flush paths when processing SDMA submissions using rings outside a partition. A local user can submit SDMA work using a ring that is not assigned to a partition to compromise confidentiality, integrity, and availability.


Remediation

Install update from vendor's website.