Patch Tuesday: Nvidia, AMD and Arm warn on GPU flaws

Nvidia, AMD and Arm on Tuesday released advisories for flaws in the Triton Inference Server and Linux GPU drivers that can cause crashes, denial-of-service or data exposure.

On Tuesday, AMD, Arm and Nvidia published security advisories for vulnerabilities in GPU software and an inference server that can cause system crashes, denial-of-service or exposure of sensitive data.

AMD disclosed CVE-2026-43603, a NULL pointer dereference in its Linux GPU kernel driver that can trigger system crashes and a denial-of-service condition. AMD credited Maxime Rossi Bellom and Ramtine Tofighi Shirazi of SecMate for reporting the issue. AMD’s advisory explains the fault can occur when an application invokes a specific graphics memory management interface to perform a ‘clear’ operation under certain compute-processing conditions and the driver fails to validate an internal data reference before use. Patches for EPYC, Athlon, Ryzen, Radeon and Instinct processors were released in July; fixes for EPYC Embedded and Ryzen Embedded families are scheduled for October.

Arm issued an advisory describing nine vulnerabilities in Mali GPUs that can allow access to memory that has already been freed, expose sensitive kernel information, or cause denial-of-service conditions. Arm released updates for kernel and userspace drivers supporting the Valhall GPU and the Arm 5th Gen GPU Architecture. The advisory also identifies affected Bifrost kernel and userspace drivers and advises applying updated software when available.

Nvidia published a software update for the Triton Inference Server for Linux addressing two high-severity vulnerabilities. One flaw can lead to a denial-of-service condition; the other can enable information disclosure, data tampering and denial-of-service outcomes. Nvidia recommends that operators running Triton on Linux install the patched version.

The notices were issued as part of the regular Patch Tuesday cycle. At the time of publication, Intel had not posted new security advisories for this cycle.

Organizations running GPU-accelerated systems, inference servers or embedded platforms that use the affected drivers should review the vendor advisories and apply available updates to reduce the risk of crashes, outages or potential data exposure.

Articles by this author