PT-2026-37577 · Linux · Linux Kernel

Published

2026-05-06

·

Updated

2026-05-07

·

CVE-2026-43237

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the amdgpu gem va ioctl function where the fence was selected too early and its reference was not managed correctly. This leads to refcount underflows and the use of stale or freed fences, resulting in a use-after-free condition on dma fence. This flaw can cause the system to crash or trigger a kernel panic when updating GPU timelines.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use After Free

Weakness Enumeration

Related Identifiers

CVE-2026-43237

Affected Products

Linux Kernel