SB20260918384 - Race condition in Linux kernel amd amdgpu driver



SB20260918384 - Race condition in Linux kernel amd amdgpu driver

Published: September 18, 2026

Security Bulletin ID SB20260918384
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Race condition (CVE-ID: CVE-2026-90286)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause GPU command submissions to execute out of order.

The vulnerability exists due to improper synchronization in the AMDGPU GFX6 compute queue handling when submitting GPU compute workloads. A local user can submit GPU compute workloads to cause GPU command submissions to execute out of order.

GFX6 compute queues share the command processing path used by graphics queues.


Remediation

Install update from vendor's website.