CVE-2026-97928: drm/amdgpu: skip the VMID 0 flush for VRAM

Published Sep 25, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu: skip the VMID 0 flush for VRAM

Clear-on-release only runs on VRAM, which amdgputtmmapbuffer() reaches via its direct MC address without programming a GART window, yet the wipe still forces a VMID 0 flush. On GFX11 (e.g. Navi33) that spurious SDMA flush can wedge the engine; only flush when a GART window is actually used.

v2: Let amdgputtmmapbuffer() return whether the VMID 0 flush is needed, and drive the clear and copy paths from that. (Christian) v3: Make the vmneedsflush output parameter mandatory instead of allowing NULL. (Christian)

(cherry picked from commit a306e406e570b74318ff7d80e5b07b540ca1d3a9)

Affected Software

1 affected component
Linux Linux kernel

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Linux kernel (drm/amdgpu) to a version that resolves this vulnerability.

    Patch a306e406e570b74318ff7d80e5b07b540ca1d3a9

Event History

Sep 25, 2026
CVE Published
via MITRE·10:22 AM
Data Sourced
via MITRE·10:22 AM
Description
Data Sourced
via NVD·11:17 AM
Description

Frequently Asked Questions

1

Does the available information describe an attacker-controlled or remote exploitation path?

No. The available information describes an AMDGPU driver failure during VRAM clear-on-release handling and does not identify a remote interface, unprivileged trigger, or attacker-controlled input.

2

What systems and activity are associated with the failure?

The issue is associated with GFX11 hardware, with Navi33 given as an example, when the clear-on-release path operates directly on VRAM. The unnecessary VMID 0 SDMA flush can wedge the engine in that situation.

3

Are affected kernel version ranges provided?

No affected or fixed version ranges are provided. The data includes two stable-kernel references and identifies the originating commit as a306e406e570b74318ff7d80e5b07b540ca1d3a9.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203