PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-43444 Linux CVE debrief

CVE-2026-43444 is a Linux kernel flaw in drm/amdkfd error handling. According to the NVD record, if a queue update fails, the code should unreserve the buffer object before returning an error. The bug was corrected in stable kernel patches linked from the NVD entry. NVD rates the issue as medium severity with local attack conditions and high availability impact.

Vendor
Linux
Product
Unknown
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-08
Original CVE updated
2026-05-21
Advisory published
2026-05-08
Advisory updated
2026-05-21

Who should care

Linux kernel maintainers, distribution security teams, and operators running AMD GPU/KFD workloads on affected kernels should prioritize this fix, especially on systems where local users can interact with amdkfd.

Technical summary

The vulnerable path is in amdkfd queue-update failure handling. The NVD description says the buffer object (bo) must be unreserved on failure, implying the flaw was a missing cleanup step in an error path. NVD maps the issue to CWE-476 and assigns CVSS 3.1 AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, which aligns with a local privilege requirement and a primary availability impact rather than confidentiality or integrity compromise.

Defensive priority

Medium. The issue is local and requires limited privileges, but it can affect availability on impacted AMD GPU/KFD systems. Patch priority is higher for multi-user hosts, compute nodes, and any environment that depends on amdkfd stability.

Recommended defensive actions

  • Apply the kernel fixes referenced by NVD for your branch or backport the stable patch set.
  • Confirm whether your deployed kernels fall within the affected ranges: 6.12 before 6.12.78, 6.13 before 6.18.19, 6.19 before 6.19.9, or 7.0-rc1 through 7.0-rc3.
  • Prioritize systems that use AMDGPU/KFD or other drm/amdkfd functionality.
  • If you maintain downstream kernels, verify the cleanup path in the queue-update failure handling is present in your build.
  • Track local-user activity and kernel error logs on affected hosts while remediation is rolled out.

Evidence notes

Source evidence is limited to the official NVD record and its referenced kernel patches. NVD states: "drm/amdkfd: Unreserve bo if queue update failed" and notes the error-handling path should unreserve the buffer object before returning failure. NVD also lists the CVSS vector AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, CWE-476, vuln status Analyzed, and the affected Linux kernel version ranges.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-43444 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-43444

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-43444 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-43444

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/2ce75a0b7e1bfddbcb9bc8aeb2e5e7fa99971acf

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/529c985da1b277b36dc99aad660f96dc70f3c467

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/781110700ada22168fbb490dd61432d23a17a5b4

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/b2b7742c465c8e3b36dc325a48abb4b9f2aaa38b

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.