Chipmaker PT: AMD Linux GPU DoS CVE-2026-43603 (6.9); Arm Mali; Nvidia Triton
SecurityWeek (9 September 2026) covers Tuesday advisories from AMD, Arm, and Nvidia. AMD-SB-6034: CVE-2026-43603 NULL pointer dereference in the Linux GPU kernel driver (clear operation under compute conditions) leading to kernel crash/DoS; CVSS 4.0 6.9 (AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/...); CWE-476; credited SecMate. Mitigations: Radeon Software for Linux 26.13 for several EPYC 4004/4005 lines (20 Jul 2026); embedded EPYC/Ryzen lines targeted October 2026 per AMD bulletin. Arm advisory covers nine Mali GPU issues (Valhall / Arm 5th Gen / Bifrost kernel and userspace) enabling use-after-free, kernel info leak, or DoS. Nvidia Triton Inference Server for Linux: two high-severity defects (DoS; info disclosure/tamper/DoS). Primary: AMD bulletin; Arm/Nvidia linked from SecurityWeek (Arm/Nvidia pages 403 from this pass).
- Product
- AMD Linux GPU driver (EPYC/Ryzen/Radeon/Instinct); Arm Mali GPU drivers; Nvidia Triton Inference Server (Linux)
- Versions
- See AMD-SB-6034 tables; Arm Valhall/5th Gen/Bifrost per Arm advisory; Nvidia Triton per customer bulletin a_id/5875
- CVSS
- (CVE-2026-43603, AMD CVSS 4.0)
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N - Exploited in Australia?
- unknown
- Patch to
- Apply AMD Radeon Software for Linux / embedded fixes per bulletin; update Arm Mali drivers; apply Nvidia Triton security update
Primary: AMD-SB-6034 — CVE-2026-43603 (Linux GPU) · Vendor: AMD Product Security · CVE: CVE-2026-43603 · SecurityWeek chipmaker PT (9 Sep 2026); also Arm doc 111552 / Nvidia A_ID 5875
