Major Chipmakers Patch Critical Vulnerabilities in GPU Drivers and Processors
AMD, Arm, and Nvidia have released security advisories addressing newly discovered vulnerabilities in their products, with fixes now available or forthcoming for affected hardware.
AMD disclosed CVE-2026-43603, a NULL pointer dereference flaw in its Linux GPU kernel driver that could trigger system crashes or denial-of-service (DoS) conditions. The issue, reported by researchers Maxime Rossi Bellom and Ramtine Tofighi Shirazi of SecMate, occurs when an application invokes a graphics memory management interface under specific compute-processing conditions, leading to improper validation of internal data references. Patches have been released for EPYC, Athlon, Ryzen, Radeon, and Instinct processors, with updates for EPYC Embedded and Ryzen Embedded processors expected in October.
Arm issued an advisory for nine vulnerabilities in its Mali GPUs, affecting Valhall, Bifrost, and 5th Gen GPU architectures. The flaws could enable memory access violations, kernel information leaks, or DoS attacks. Fixes are available for the Valhall and 5th Gen GPU kernel and userspace drivers, while the Bifrost GPU remains impacted.
Nvidia released a software update for its Triton Inference Server for Linux, resolving two high-severity vulnerabilities. One could cause a DoS condition, while the other may lead to information disclosure, data tampering, or additional DoS risks.
As of publication, Intel had not issued new advisories since the last Patch Tuesday. The updates follow recent disclosures of critical flaws in industrial control systems (ICS) and enterprise security products.
Source: https://www.securityweek.com/chipmaker-patch-tuesday-nvidia-amd-arm-issue-security-advisories/
Nvidia TPRM report: https://www.rankiteo.com/company/nvidia
AMD TPRM report: https://www.rankiteo.com/company/amd
"id": "nviamd1789014785",
"linkid": "nvidia, amd",
"type": "Vulnerability",
"date": "9/2026",
"severity": "25",
"impact": "1",
"explanation": "Attack without any consequences"
{'affected_entities': [{'industry': 'Semiconductors',
'name': 'AMD',
'type': 'Chipmaker'},
{'industry': 'Semiconductors',
'name': 'Arm',
'type': 'Chipmaker'},
{'industry': 'Semiconductors',
'name': 'Nvidia',
'type': 'Chipmaker'}],
'attack_vector': ['Exploitable Software Flaw', 'Memory Management Interface'],
'description': 'AMD, Arm, and Nvidia have released security advisories '
'addressing newly discovered vulnerabilities in their '
'products, with fixes now available or forthcoming for '
'affected hardware. AMD disclosed CVE-2026-43603, a NULL '
'pointer dereference flaw in its Linux GPU kernel driver that '
'could trigger system crashes or denial-of-service (DoS) '
'conditions. Arm issued an advisory for nine vulnerabilities '
'in its Mali GPUs, affecting Valhall, Bifrost, and 5th Gen GPU '
'architectures. Nvidia released a software update for its '
'Triton Inference Server for Linux, resolving two '
'high-severity vulnerabilities.',
'impact': {'operational_impact': ['System crashes',
'Denial-of-Service (DoS) conditions'],
'systems_affected': ['GPU drivers',
'Processors',
'Inference servers']},
'post_incident_analysis': {'corrective_actions': ['Driver updates',
'Security patches'],
'root_causes': ['Improper validation of internal '
'data references',
'Memory access violations',
'Kernel information leaks']},
'recommendations': ['Apply patches and updates promptly',
'Monitor for further advisories'],
'references': [{'source': 'Security Advisory'}],
'response': {'containment_measures': ['Patches released', 'Software updates'],
'remediation_measures': ['Security advisories issued',
'Driver updates']},
'title': 'Major Chipmakers Patch Critical Vulnerabilities in GPU Drivers and '
'Processors',
'type': ['Vulnerability Disclosure', 'Denial-of-Service (DoS)'],
'vulnerability_exploited': ['CVE-2026-43603 (NULL pointer dereference)',
'Mali GPU vulnerabilities (memory access '
'violations, kernel information leaks)',
'Nvidia Triton Inference Server vulnerabilities '
'(DoS, information disclosure)']}