HomeDefectsLIN1022-25887
Acknowledged

LIN1022-25887 : Security Advisory - linux - CVE-2026-46220

Created: May 29, 2026    Updated: Jun 9, 2026
Found In Version: 10.22.33.2
Severity: Standard
Applicable for: Wind River Linux LTS 22
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission  sdma_v4_0_ring_emit_fence() contains two BUG_ON(addr & 0x3) assertions that verify fence writeback addresses are dword-aligned.  These assertions can be reached from unprivileged userspace via crafted DRM_IOCTL_AMDGPU_CS submissions, causing a fatal kernel panic in a scheduler worker thread.  Replace both BUG_ON() calls with WARN_ON() to log the condition without crashing the kernel.  A misaligned fence address at this point indicates a driver bug, but crashing the kernel is never the correct response when the assertion is reachable from userspace.  The CS IOCTL path is the correct place to filter invalid submissions; the ring emission callback is too late to do anything about it.  (cherry picked from commit b90250bd933afd1ba94d86d6b13821997b22b18e)