In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: zero-initialize GART table on allocation GART TLB is flushed after… (CVE-2026-53374)
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: zero-initialize GART table on allocation GART TLB is flushed after unmapping but not after mapping. Since amdgpu_bo_create_kernel() does not zero-initialize the buffer, when a single PTE is written the TLB may speculatively load other uninitialized entries from the same cacheline. Those garbage entries can appear valid, and a subsequent write to another PTE in the same cacheline may cause the GPU to use a stale garbage PTE from the TLB. Fix this by calling memset_io() to zero-initialize the GART table with gart_pte_flags immediately after allocation. Using AMDGPU_GEM_CREATE_VRAM_CLEARED, SDMA-based clear will not work since SDMA needs GART to be initialized to work. (cherry picked from commit d9af8263b82b6eaa60c5718e0c6631c5037e4b24)
AI Analysis
Technical Summary
The Linux kernel AMDGPU driver had a vulnerability where the GART Translation Lookaside Buffer (TLB) was flushed after unmapping but not after mapping. Since amdgpu_bo_create_kernel() did not zero-initialize the buffer, speculative loading of uninitialized entries from the same cacheline could occur, causing the GPU to use stale or garbage page table entries. This was fixed by calling memset_io() to zero-initialize the GART table immediately after allocation. The issue affects multiple Linux kernel versions prior to 6.8.0-1061.64~22.04.1 and similar builds. The vulnerability has a CVSS 3.1 score of 8.8 (high severity) with local attack vector, low attack complexity, requiring low privileges, no user interaction, and impacts confidentiality, integrity, and availability. The vendor advisory from Ubuntu confirms the fix is available in updated kernel packages and recommends system updates and reboot.
Potential Impact
Exploitation of this vulnerability could allow a local attacker with low privileges to cause the GPU to use stale or garbage page table entries, potentially leading to confidentiality, integrity, and availability impacts on the system. The CVSS score of 8.8 indicates a high severity vulnerability with potential for significant system compromise if exploited.
Mitigation Recommendations
A patch is available and has been incorporated into updated Linux kernel packages for affected Ubuntu releases. Users should apply the latest kernel updates and reboot their systems to ensure the fix is applied. Due to an ABI change, recompilation and reinstallation of third-party kernel modules may be required after updating. Follow vendor guidance for updating kernel packages to versions >=6.8.0-1061.64~22.04.1 or later as specified in the advisory.
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: zero-initialize GART table on allocation GART TLB is flushed after… (CVE-2026-53374)
Description
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: zero-initialize GART table on allocation GART TLB is flushed after unmapping but not after mapping. Since amdgpu_bo_create_kernel() does not zero-initialize the buffer, when a single PTE is written the TLB may speculatively load other uninitialized entries from the same cacheline. Those garbage entries can appear valid, and a subsequent write to another PTE in the same cacheline may cause the GPU to use a stale garbage PTE from the TLB. Fix this by calling memset_io() to zero-initialize the GART table with gart_pte_flags immediately after allocation. Using AMDGPU_GEM_CREATE_VRAM_CLEARED, SDMA-based clear will not work since SDMA needs GART to be initialized to work. (cherry picked from commit d9af8263b82b6eaa60c5718e0c6631c5037e4b24)
CVSS v3.1
Score 8.8high
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel AMDGPU driver had a vulnerability where the GART Translation Lookaside Buffer (TLB) was flushed after unmapping but not after mapping. Since amdgpu_bo_create_kernel() did not zero-initialize the buffer, speculative loading of uninitialized entries from the same cacheline could occur, causing the GPU to use stale or garbage page table entries. This was fixed by calling memset_io() to zero-initialize the GART table immediately after allocation. The issue affects multiple Linux kernel versions prior to 6.8.0-1061.64~22.04.1 and similar builds. The vulnerability has a CVSS 3.1 score of 8.8 (high severity) with local attack vector, low attack complexity, requiring low privileges, no user interaction, and impacts confidentiality, integrity, and availability. The vendor advisory from Ubuntu confirms the fix is available in updated kernel packages and recommends system updates and reboot.
Potential Impact
Exploitation of this vulnerability could allow a local attacker with low privileges to cause the GPU to use stale or garbage page table entries, potentially leading to confidentiality, integrity, and availability impacts on the system. The CVSS score of 8.8 indicates a high severity vulnerability with potential for significant system compromise if exploited.
Mitigation Recommendations
A patch is available and has been incorporated into updated Linux kernel packages for affected Ubuntu releases. Users should apply the latest kernel updates and reboot their systems to ensure the fix is applied. Due to an ABI change, recompilation and reinstallation of third-party kernel modules may be required after updating. Follow vendor guidance for updating kernel packages to versions >=6.8.0-1061.64~22.04.1 or later as specified in the advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-45w5-677j-gmrq
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-53374"]
- Ecosystems
- []
- Database Specific Severity
- null
- Cvss Version
- 3.1
Threat ID: 6a5d27ae2a4a8d59891328ba
Added to database: 07/19/2026, 19:38:22 UTC
Last enriched: 08/01/2026, 00:25:12 UTC
Last updated: 09/02/2026, 10:52:10 UTC
Views: 92
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.