Linux kernel amdgpu firmware, ACPI and IP-block initialisation (drm/amdgpu/vcn4): A correctness defect in the amdgpu
Impact
A correctness defect in the amdgpu firmware, ACPI and IP-block initialisation reachable through the driver's user-facing interface. The practical effect is an unstable or crashing GPU driver on a shared node. Upstream fix: drm/amdgpu/vcn4: avoid rereading IB param length
Who can reach it
Local. Reachable by a local user with driver-load influence, or an attacker who controls platform ACPI tables / VBIOS content - usually root or firmware-level access rather than a tenant. Not reachable over the network and not reachable from a container that has no GPU device node mapped in.
What to do
Kernel-side fix: this lands in mainline Linux and flows into distro kernels (RHEL/Rocky, Ubuntu HWE, SLES) and into AMD's out-of-tree DKMS amdgpu package shipped with ROCm. Patch the kernel or the DKMS module, then **reload the amdgpu module or reboot the node** - you cannot fix a running driver in place. Reloading amdgpu requires no process holding /dev/kfd or a render node, so in practice this is a cordon + drain + reboot per node. Plan it as a rolling maintenance across the fleet; there is no VBIOS flash, no SBIOS/AGESA step and no firmware update involved. Nodes running the ROCm DKMS stack often lag mainline by a release or two, so confirm the fix is actually present in the AMD driver version you deploy rather than assuming a new distro kernel covers it.
References
Related entries
- Linux kernel amdgpu firmware, ACPI and IP-block initialisation (drm/amdgpu/vcn4): An out-of-bounds access in the amdgpuCVE-2026-46199 · Linux kernel amdgpu firmware, ACPI and IP-block initialisation (drm/amdgpu/vcn4)High
- Linux kernel amdgpu firmware, ACPI and IP-block initialisation (drm/amdgpu/vcn4): An out-of-bounds access in the amdgpuCVE-2026-46204 · Linux kernel amdgpu firmware, ACPI and IP-block initialisation (drm/amdgpu/vcn4)High
- Linux kernel amdgpu firmware, ACPI and IP-block initialisation (drm/amdgpu/vce): An out-of-bounds access in the amdgpuCVE-2026-68108 · Linux kernel amdgpu firmware, ACPI and IP-block initialisation (drm/amdgpu/vce)High
- Linux kernel drm/vmwgfx: undersized DMA command lets one command rewrite another's verified fieldsCVE-2026-74443 · Linux kernel drm/vmwgfx (DMA command suffix bounds check in vmw_cmd_dma)High
- Linux kernel amdxdna: use-after-free on the IOMMU domain when the accelerator device is removedCVE-2026-80608 · Linux kernel accel/amdxdna (AMD XDNA NPU driver, IOMMU domain lifetime)High
- Linux kernel nouveau/dmem: large-folio migration unmaps PAGE_SIZE instead of the mapped size, leaking IOVACVE-2026-89804 · Linux kernel drm/nouveau/dmem (device-private THP migration, DMA unmap size)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.