CVE-2026-80539: drm/amdgpu: disallow multiple FENCE chunks in one submit
drm/amdgpu: disallow multiple FENCE chunks in one submit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.157.1-1
Event History
Frequently Asked Questions
What does an attacker need to do to trigger the leak?
They need to submit an AMDGPU command submission containing more than one AMDGPU_CHUNK_ID_FENCE chunk. Each FENCE chunk before the last causes a buffer-object reference that is not released.
Who is exposed to this issue?
Systems using the Linux kernel AMDGPU DRM driver are exposed when an entity can issue crafted AMDGPU command submissions. The leaked buffer object can remain alive even after its handle is closed and the submitting process exits.
How can I tell whether a system is affected?
An affected implementation accepts multiple FENCE chunks in a single submission rather than rejecting the duplicate. The provided fixes change this behavior to reject duplicate FENCE chunks.