Reachable assertion in Linux kernel - CVE-2026-46220
Published: May 29, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to reachable assertion use in sdma_v4_0_ring_emit_fence() when processing crafted DRM_IOCTL_AMDGPU_CS submissions. A local user can submit a specially crafted command submission request to cause a denial of service.
The issue can trigger a fatal kernel panic in a scheduler worker thread when a misaligned fence writeback address reaches the fence emission path.
How to mitigate CVE-2026-46220
Sources
- https://git.kernel.org/stable/c/0b91ea46bb68abf98a082bf239092253bbd6aaa2
- https://git.kernel.org/stable/c/4f7ca00fa91daf0795ec6b3b130c5ebba1f155fe
- https://git.kernel.org/stable/c/78d2e624fa073c14970aa097adcf3ea31c157a66
- https://git.kernel.org/stable/c/a4fd82fb0757c180bf622907397c528b89a827b2
- https://git.kernel.org/stable/c/d331fb241a4602253976ddd65144a8ba2b05665d