SecMate automatically discovered CVE-2026-43603, a vulnerability in AMD’s Linux GPU kernel driver. AMD published AMD-SB-6034 on September 8, 2026, crediting Maxime Rossi Bellom and Ramtine Tofighi Shirazi from SecMate.

The finding and its impact

A missing check during graphics memory clearing can leave the driver using a NULL reference under certain compute conditions. A local user could consequently cause a kernel crash and denial of service. AMD assigns CVSS 4.0 6.9 (Medium) and CWE-476. AMD’s advisory describes an availability impact.

A kernel crash can interrupt other workloads running on the same GPU host.

SecurityWeek also covered the disclosure in its September 9 roundup, Chipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security Advisories, naming both SecMate researchers.

AMD’s fix and update guidance

As of September 13, AMD’s mitigation table lists:

Products listed by AMDMitigationRelease date or target
Selected EPYC, Athlon, Ryzen and Radeon productsRadeon Software for Linux 26.13July 20, 2026
Listed Instinct acceleratorsLinux GPU Driver 31.40July 15, 2026
Listed EPYC Embedded and Ryzen Embedded productsVersion pendingOctober 2026 target
Radeon PRO V520, V620 and V710Contact AMD Customer EngineeringNot specified

Check the advisory for your exact model; the embedded dates remain targets.

The Radeon Software for Linux 26.13 release notes provide downloads and installation guidance. AMD also recommends distribution-provided drivers for many configurations. If that is how you receive your driver, check your distribution’s security updates for the fix rather than comparing its kernel version directly with AMD’s package numbers.

The AMD GPU Driver 31.40.0 release notes describe fixes for NULL-pointer access among several memory-safety issues, but do not identify a commit for this CVE.

Install the applicable vendor-supported update and follow its restart instructions. For products awaiting a release, track AMD’s advisory and confirm the delivery plan with your supplier.

For our other published findings and vendor advisories, see SecMate’s vulnerability disclosures.