<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/"><channel><title>amd on SecMate Blog</title><link>https://blog.secmate.dev/tags/amd/</link><description>SecMate vulnerability research, technical advisories, security benchmarks, and evidence-backed analysis of exploitable software flaws.</description><generator>Hugo</generator><language>en-us</language><managingEditor>noreply@blog.secmate.dev (SecMate Team)</managingEditor><lastBuildDate>Tue, 15 Sep 2026 07:44:29 +0000</lastBuildDate><atom:link href="https://blog.secmate.dev/tags/amd/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-43603: Local Denial of Service in AMD's Linux GPU Driver</title><link>https://blog.secmate.dev/posts/amd-linux-gpu-driver-cve-2026-43603/</link><pubDate>Sun, 13 Sep 2026 00:00:00 +0200</pubDate><atom:updated>2026-09-15T09:42:14+02:00</atom:updated><dc:creator>Maxime Rossi Bellom</dc:creator><dc:creator>Ramtine Tofighi Shirazi</dc:creator><category>Security</category><category>Vulnerability Research</category><guid>https://blog.secmate.dev/posts/amd-linux-gpu-driver-cve-2026-43603/</guid><description>SecMate's automated discovery of CVE-2026-43603: local denial of service in AMD's Linux GPU driver, official advisory and driver updates.</description><content:encoded><![CDATA[<p>SecMate automatically discovered <strong>CVE-2026-43603</strong>, a vulnerability in AMD&rsquo;s Linux GPU kernel driver. AMD published <a href="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6034.html" rel="noopener noreferrer" target="_blank">AMD-SB-6034</a> on September 8, 2026, crediting Maxime Rossi Bellom and Ramtine Tofighi Shirazi from SecMate.</p>
<h2 id="the-finding-and-its-impact">The finding and its impact</h2>
<p>A missing check during graphics memory clearing can leave the driver using a NULL reference under certain compute conditions. A local user could consequently cause a kernel crash and denial of service. AMD assigns <strong>CVSS 4.0 6.9 (Medium)</strong> and <strong>CWE-476</strong>. <a href="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6034.html" rel="noopener noreferrer" target="_blank">AMD&rsquo;s advisory</a> describes an availability impact.</p>
<p>A kernel crash can interrupt other workloads running on the same GPU host.</p>
<p>SecurityWeek also covered the disclosure in its September 9 roundup, <a href="https://www.securityweek.com/chipmaker-patch-tuesday-nvidia-amd-arm-issue-security-advisories/" rel="noopener noreferrer" target="_blank">Chipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security Advisories</a>, naming both SecMate researchers.</p>
<h2 id="amds-fix-and-update-guidance">AMD&rsquo;s fix and update guidance</h2>
<p>As of September 13, <a href="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6034.html" rel="noopener noreferrer" target="_blank">AMD&rsquo;s mitigation table</a> lists:</p>
<table>
<thead>
<tr>
<th>Products listed by AMD</th>
<th>Mitigation</th>
<th>Release date or target</th>
</tr>
</thead>
<tbody>
<tr>
<td>Selected EPYC, Athlon, Ryzen and Radeon products</td>
<td>Radeon Software for Linux <strong>26.13</strong></td>
<td>July 20, 2026</td>
</tr>
<tr>
<td>Listed Instinct accelerators</td>
<td>Linux GPU Driver <strong>31.40</strong></td>
<td>July 15, 2026</td>
</tr>
<tr>
<td>Listed EPYC Embedded and Ryzen Embedded products</td>
<td>Version pending</td>
<td>October 2026 target</td>
</tr>
<tr>
<td>Radeon PRO V520, V620 and V710</td>
<td>Contact AMD Customer Engineering</td>
<td>Not specified</td>
</tr>
</tbody>
</table>
<p>Check the advisory for your exact model; the embedded dates remain targets.</p>
<p>The <a href="https://www.amd.com/en/resources/support-articles/release-notes/RN-AMDGPU-UNIFIED-LINUX-26-13.html" rel="noopener noreferrer" target="_blank">Radeon Software for Linux 26.13 release notes</a> provide downloads and installation guidance. AMD also recommends distribution-provided drivers for many configurations. If that is how you receive your driver, check your distribution&rsquo;s security updates for the fix rather than comparing its kernel version directly with AMD&rsquo;s package numbers.</p>
<p>The <a href="https://instinct.docs.amd.com/projects/amdgpu-docs/en/docs-31.40.0/documentation/release-notes.html#driver-security" rel="noopener noreferrer" target="_blank">AMD GPU Driver 31.40.0 release notes</a> describe fixes for NULL-pointer access among several memory-safety issues, but do not identify a commit for this CVE.</p>
<p>Install the applicable vendor-supported update and follow its restart instructions. For products awaiting a release, track AMD&rsquo;s advisory and confirm the delivery plan with your supplier.</p>
<p>For our other published findings and vendor advisories, see <a href="https://secmate.dev/disclosures?utm_source=blog&amp;utm_medium=body&amp;utm_campaign=amd-linux-gpu-driver-cve-2026-43603&amp;utm_content=security" rel="noopener noreferrer" target="_blank" data-cta-type="body_disclosures" data-post-slug="amd-linux-gpu-driver-cve-2026-43603" data-post-category="security">SecMate&rsquo;s vulnerability disclosures</a>.</p>
]]></content:encoded><media:content url="https://blog.secmate.dev/images/og_image.jpg" medium="image"/></item></channel></rss>