{"id":"CVE-2026-90286","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-90286","summary":"drm/amdgpu/gfx6: Use PFP on the compute queues too","details":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/gfx6: Use PFP on the compute queues too\n\nOn GFX6, the compute rings use the same CP path as\nthe graphics ring. The only difference is that they\ndon't support draw commands. (As opposed to GFX7 and\nnewer which have a separate command parser that is\ncalled MEC for compute queues.)\n\nThis means that we have to take into consideration\nthat the PFP also exists on compute queues on GFX6:\n\nUse PFP for register writes on both graphics and\ncompute queues.\n\nIn the pipeline sync, use the PFP to wait for the\nprevious fence (and not the ME) to prevent the PFP\nfrom starting to execute the next submission while\nthe ME is still in the previous submission.\n\nAfter a VM flush, emit PFP_SYNC_ME on compute\nqueues as well.","published":"2026-09-17T16:08:15.335Z","modified":"2026-09-19T03:46:52.433976758Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Linux","name":"Kernel","fixedVersion":"5.10.270"}],"fix":null,"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/2aa869c6b23e0b1b7f39f762618852811d75deb9"},{"type":"WEB","url":"https://git.kernel.org/stable/c/60f20946cd318518ddc2c0da12103c666b2b9564"},{"type":"WEB","url":"https://git.kernel.org/stable/c/8d752f1bb73fabe5a425acbf5c767c0fe68bf3c5"},{"type":"WEB","url":"https://git.kernel.org/stable/c/b5d1d3e4519dc8f1b55d6b236848bed67b11a2e8"},{"type":"WEB","url":"https://git.kernel.org/stable/c/e1d3018e3621c90cec070b6915836ae129656663"},{"type":"WEB","url":"https://git.kernel.org/stable/c/e399e9d7e291ccbeba6560fb8278c8d2aa744521"},{"type":"WEB","url":"https://git.kernel.org/stable/c/f37211b9c01433f0bbb4709d25df7a0257cf915b"},{"type":"WEB","url":"https://git.kernel.org/stable/c/fbabc39b4f0fc771b00525ffd448be6a84355048"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90286.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-90286"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-19T03:46:52.433976758Z"}}