ZeroHour
SecurityWeekpublished ()ingested Ionut Arghire

Chipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security Advisories

mediumAdvisoryimportance 30CVE-2026-43603
AI summary · glm-5.3-flash

AMD, Arm, and Nvidia issued Patch Tuesday advisories fixing a Linux GPU driver DoS flaw, nine Mali GPU vulnerabilities, and two high-severity Triton defects.

AMD fixed CVE-2026-43603, a NULL pointer dereference in its Linux GPU kernel driver that can crash systems and cause denial-of-service, credited to SecMate researchers, with patches for EPYC, Ryzen, Radeon, and Instinct shipped in July and embedded variants due in October. Arm published an advisory covering nine Mali GPU vulnerabilities allowing use-after-free access, kernel information leaks, or DoS, releasing fixes for Valhall and 5th Gen GPU Architecture drivers, with Bifrost also affected. Nvidia updated Triton Inference Server for Linux to resolve two high-severity flaws, one causing DoS and one enabling information disclosure, data tampering, and DoS. Intel had issued no new advisories since the previous Patch Tuesday.

  • AMD patched CVE-2026-43603 NULL pointer dereference in Linux GPU kernel driver causing DoS
  • Arm fixed nine Mali GPU vulnerabilities affecting Valhall, Bifrost, and 5th Gen GPU Architecture
  • Nvidia patched two high-severity flaws in Triton Inference Server for Linux
  • Intel released no new advisories this Patch Tuesday

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-43603

NVD description · AI analysis pending
Full article288 words · extracted from securityweek.com · click to collapse

Major chipmakers AMD, Arm, and Nvidia published new security advisories on Tuesday to notify customers of vulnerabilities recently discovered in their products.

AMD announced fixes for CVE-2026-43603, a NULL pointer dereference flaw in its Linux GPU kernel driver that could lead to system crashes and a denial-of-service (DoS) condition.

The company credited Maxime Rossi Bellom and Ramtine Tofighi Shirazi from SecMate for reporting the security defect.

“According to the researchers’ report, when an application invokes a specific graphics memory management interface to perform a ‘clear’ operation under certain compute-processing conditions, the driver may fail to validate an internal data reference before use,” AMD notes in its advisory.

The company rolled out fixes for EPYC Athlon, Ryzen, Radeon, and Instinct processors in July. It plans to release the patches for the EPYC Embedded and Ryzen Embedded processors in October.

Arm published an advisory covering nine vulnerabilities in its Mali GPUs that could allow access to already freed memory or to sensitive kernel information, or could lead to a denial-of-service (DoS) condition.

Advertisement. Scroll to continue reading.

The company has released fixes for the Valhall GPU and Arm 5th Gen GPU Architecture kernel and userspace drivers. The Bifrost GPU kernel and userspace drivers are also affected.

Nvidia announced a software update for the Triton Inference Server for Linux that resolves two high-severity security defects. The first could lead to a DoS condition, while the second could lead to information disclosure, data tampering, and DoS conditions.

At the time of publishing, Intel had not released new security advisories since the previous Patch Tuesday.

Related: ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws

Related: Ivanti Patches Critical Flaws Across Enterprise Security Products

Related: Chrome 153 Patches Seventh Zero-Day of 2026

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.securityweek.com/chipmaker-patch-tuesday-nvidia-amd-arm-issue-security-advisories/