Race condition in Linux kernel - CVE-2026-90286
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local user to cause GPU command submissions to execute out of order.
The vulnerability exists due to improper synchronization in the AMDGPU GFX6 compute queue handling when submitting GPU compute workloads. A local user can submit GPU compute workloads to cause GPU command submissions to execute out of order.
GFX6 compute queues share the command processing path used by graphics queues.
Affected software
How to mitigate CVE-2026-90286
External References
- https://git.kernel.org/stable/c/2aa869c6b23e0b1b7f39f762618852811d75deb9
- https://git.kernel.org/stable/c/60f20946cd318518ddc2c0da12103c666b2b9564
- https://git.kernel.org/stable/c/8d752f1bb73fabe5a425acbf5c767c0fe68bf3c5
- https://git.kernel.org/stable/c/b5d1d3e4519dc8f1b55d6b236848bed67b11a2e8
- https://git.kernel.org/stable/c/e1d3018e3621c90cec070b6915836ae129656663
- https://git.kernel.org/stable/c/e399e9d7e291ccbeba6560fb8278c8d2aa744521
- https://git.kernel.org/stable/c/f37211b9c01433f0bbb4709d25df7a0257cf915b
- https://git.kernel.org/stable/c/fbabc39b4f0fc771b00525ffd448be6a84355048