Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.1%top 97%

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: zero-initialize GART table on allocation GART TLB is flushed after… (CVE-2026-53374)

0
Medium
Published: 07/20/2026 (07/20/2026, 00:00:00 UTC)
Source: GCVE Database
Product: linux

Description

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: zero-initialize GART table on allocation GART TLB is flushed after unmapping but not after mapping. Since amdgpu_bo_create_kernel() does not zero-initialize the buffer, when a single PTE is written the TLB may speculatively load other uninitialized entries from the same cacheline. Those garbage entries can appear valid, and a subsequent write to another PTE in the same cacheline may cause the GPU to use a stale garbage PTE from the TLB. Fix this by calling memset_io() to zero-initialize the GART table with gart_pte_flags immediately after allocation. Using AMDGPU_GEM_CREATE_VRAM_CLEARED, SDMA-based clear will not work since SDMA needs GART to be initialized to work. (cherry picked from commit d9af8263b82b6eaa60c5718e0c6631c5037e4b24)

CVSS v3.1

Score 8.8high

Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected software

Affected versions
<6.8.0-1061.64~22.04.1<6.8.0-1063.71~22.04.1<6.8.0-1062.69~22.04.1<6.8.0-1064.72~22.04.1<6.8.0-136.136~22.04.1

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/01/2026, 00:25:12 UTC

Technical Analysis

The Linux kernel AMDGPU driver had a vulnerability where the GART Translation Lookaside Buffer (TLB) was flushed after unmapping but not after mapping. Since amdgpu_bo_create_kernel() did not zero-initialize the buffer, speculative loading of uninitialized entries from the same cacheline could occur, causing the GPU to use stale or garbage page table entries. This was fixed by calling memset_io() to zero-initialize the GART table immediately after allocation. The issue affects multiple Linux kernel versions prior to 6.8.0-1061.64~22.04.1 and similar builds. The vulnerability has a CVSS 3.1 score of 8.8 (high severity) with local attack vector, low attack complexity, requiring low privileges, no user interaction, and impacts confidentiality, integrity, and availability. The vendor advisory from Ubuntu confirms the fix is available in updated kernel packages and recommends system updates and reboot.

Potential Impact

Exploitation of this vulnerability could allow a local attacker with low privileges to cause the GPU to use stale or garbage page table entries, potentially leading to confidentiality, integrity, and availability impacts on the system. The CVSS score of 8.8 indicates a high severity vulnerability with potential for significant system compromise if exploited.

Mitigation Recommendations

A patch is available and has been incorporated into updated Linux kernel packages for affected Ubuntu releases. Users should apply the latest kernel updates and reboot their systems to ensure the fix is applied. Due to an ABI change, recompilation and reinstallation of third-party kernel modules may be required after updating. Follow vendor guidance for updating kernel packages to versions >=6.8.0-1061.64~22.04.1 or later as specified in the advisory.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-45w5-677j-gmrq
Osv Schema Version
1.4.0
Aliases
["CVE-2026-53374"]
Ecosystems
[]
Database Specific Severity
null
Cvss Version
3.1

Threat ID: 6a5d27ae2a4a8d59891328ba

Added to database: 07/19/2026, 19:38:22 UTC

Last enriched: 08/01/2026, 00:25:12 UTC

Last updated: 09/02/2026, 10:52:10 UTC

Views: 92

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses