CVE-2026-46229

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure KFD VRAM allocations set AMDGPU_GEM_CREATE_VRAM_WIPE_ON_RELEASE but not AMDGPU_GEM_CREATE_VRAM_CLEARED, leaving freshly allocated VRAM with stale data from prior use observable by compute kernels. The GEM ioctl path already sets VRAM_CLEARED for all userspace allocations via amdgpu_gem_create_ioctl() and amdgpu_mode_dumb_create(). The KFD path was missing this flag, allowing stale page table remnants to leak into user buffers. This causes crashes in RCCL P2P transport where non-zero data in ptrExchange/head/tail fields corrupts the protocol handshake.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

10 Jun 2026, 21:12

Type Values Removed Values Added
CWE NVD-CWE-noinfo
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
First Time Linux linux Kernel
Linux
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
References () https://git.kernel.org/stable/c/047d44d8d29a6a1a5757256837aa9dd78e3cd0b5 - () https://git.kernel.org/stable/c/047d44d8d29a6a1a5757256837aa9dd78e3cd0b5 - Patch
References () https://git.kernel.org/stable/c/1db431380879fd9d28b763a88a0c0431be5be8df - () https://git.kernel.org/stable/c/1db431380879fd9d28b763a88a0c0431be5be8df - Patch
References () https://git.kernel.org/stable/c/32b153658f017ad2f5bf8aab479e8d16ac95bc3a - () https://git.kernel.org/stable/c/32b153658f017ad2f5bf8aab479e8d16ac95bc3a - Patch
References () https://git.kernel.org/stable/c/77d0b5d11387071770246fd0185a69fa28e8e109 - () https://git.kernel.org/stable/c/77d0b5d11387071770246fd0185a69fa28e8e109 - Patch
References () https://git.kernel.org/stable/c/ad52d61d82181dbdb7f05826de38352d5e550cc2 - () https://git.kernel.org/stable/c/ad52d61d82181dbdb7f05826de38352d5e550cc2 - Patch

28 May 2026, 10:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-28 10:16

Updated : 2026-06-10 21:12


NVD link : CVE-2026-46229

Mitre link : CVE-2026-46229

CVE.ORG link : CVE-2026-46229


JSON object : View

Products Affected

linux

  • linux_kernel