Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
On September 9, 2026, AMD, Arm, and Nvidia simultaneously published security advisories for vulnerabilities in their respective graphics and AI acceleration software stacks. The timing is no coincidence: this is the second edition of the so-called "Chipmaker Patch Tuesday," a coordinated disclosure grouping three vendors across distinct hardware but with a common target — accelerated silicon security. Arm released ten CVEs for Mali GPU drivers; AMD fixed a NULL pointer dereference in the Linux driver; Nvidia patched two high-severity flaws in Triton Inference Server for Linux.
- Arm published advisories for 10 CVEs in Mali GPU drivers (kernel and userspace): the minimum fix is version r56p0, per the vendor's official advisory.
- AMD fixed CVE-2026-43603, a NULL pointer dereference in the Linux GPU kernel driver discovered by Maxime Rossi Bellom and Ramtine Tofighi Shirazi of SecMate; patches for EPYC Embedded and Ryzen Embedded are expected in October 2026.
- Nvidia resolved two high-severity vulnerabilities in Triton Inference Server for Linux: the first causes DoS, the second enables information disclosure, data tampering, and DoS.
- Two Arm vulnerabilities (CVE-2026-9034 and CVE-2026-11891) are exploitable via WebGL or WebGPU from an unprivileged process, expanding the attack surface to the browser.
Arm: Ten CVEs and the WebGL/WebGPU Risk
Arm's published advisory lists ten CVE identifiers for Mali GPU drivers covering versions from r12p0 to r55p0: CVE-2026-0001, CVE-2026-0860, CVE-2026-5729, CVE-2026-7476, CVE-2026-7477, CVE-2026-9034, CVE-2026-9040, CVE-2026-11891, CVE-2026-12285, and CVE-2026-12387. Affected drivers include Bifrost, Valhall, and the 5th Gen GPU Architecture. The official advisory does not provide CVSS scores.
The attack mechanism varies by defect family. CVE-2026-9034 and CVE-2026-11891 allow an unprivileged user process to access freed memory through valid GPU operations executed via WebGL or WebGPU. The attack surface extends beyond the local kernel: the browser becomes an exploit vector. The other vulnerabilities in the set stem from use-after-free in the kernel driver or exposure of sensitive kernel information. The source does not specify the nature of the exposed information.
The fix is available in version r56p0 and later for all cited driver families. Upgrading is mandatory for mobile, edge, and embedded devices mounting Mali GPUs — a population covering the majority of the mid-range Android market and accelerated IoT.
AMD: The NULL Pointer Dereference in the Linux Driver
AMD published an advisory for CVE-2026-43603, a NULL pointer dereference in the Linux GPU kernel driver. According to SecurityWeek, the flaw manifests "when an application invokes a specific graphics memory management interface to perform a 'clear' operation under certain compute-processing conditions, the driver may fail to validate an internal data reference before use." The documented consequence is a system crash with a DoS condition.
The brief does not specify whether the vulnerability allows privilege escalation beyond DoS. Patches for EPYC, Athlon, Ryzen, Radeon, and Instinct were released in July 2026; patches for EPYC Embedded and Ryzen Embedded are slated for October 2026. This asymmetric staging introduces an exposure window for industrial and automotive embedded systems, where update cycles are slower.
Nvidia: Two High-Severity Flaws in Triton Inference Server
Nvidia released software updates for Triton Inference Server for Linux. The two vulnerabilities are classified high-severity but lack public CVE identifiers in available sources. The first can cause DoS. The second combines information disclosure, data tampering, and DoS — a triple profile that makes it more versatile for an attacker.
Triton Inference Server is a standard component of Nvidia's MLOps stack: it orchestrates models on GPUs in multi-tenant, cloud, and on-premise deployments. A compromise at this layer does not strike the silicon directly, but the logical infrastructure that harnesses its compute capacity. The brief does not document whether the vulnerabilities are replicable in specific containerized or virtualized configurations.
The Chipmaker Patch Tuesday Pattern and the Limits of Coordination
The simultaneity of the September 9 disclosures confirms an emerging pattern: accelerated-silicon vendors are synchronizing patch cycles on a shared monthly date, replicating the Microsoft model but with actors competing on different hardware. The coordination offers operational advantages for those managing heterogeneous fleets — a single maintenance window — but also exposes the practice's limits.
Arm has a complete primary advisory with CVEs and versions; AMD and Nvidia do not have directly accessible advisories in the cited sources. Technical details on the latter two vendors transit through SecurityWeek and CloudLinkTech, with the risk of information degradation or lag. Moreover, AMD's patch staging (July for server/desktop, October for embedded) breaks the illusion of a single event: the disclosure date is shared, the fix availability is not.
What to Do Now
- Verify Mali GPU driver versions on Arm devices: the official advisory indicates r56p0 as the minimum security threshold.
- For AMD embedded systems (EPYC Embedded, Ryzen Embedded), plan for the patches expected in October 2026 and evaluate access controls to the graphics interface in the meantime.
- Update Nvidia Triton Inference Server to the latest current version, with particular attention to multi-tenant deployments where the second vulnerability could facilitate cross-tenant information disclosure.
- For Arm vulnerabilities exploitable via WebGL/WebGPU, evaluate browser process isolation policies on mobile and edge devices not yet patchable.
FAQ
- Why "Chipmaker Patch Tuesday"?
- It is a journalistic term describing the temporal convergence of AMD, Arm, and Nvidia advisories on September 9, 2026. The pattern had already emerged in prior disclosures and is now consolidated as market coordination.
- Are the Arm vulnerabilities remote?
- No. They require a local unprivileged process. Two of them (CVE-2026-9034 and CVE-2026-11891) can be triggered via WebGL or WebGPU from the browser, but the process remains local.
- Did Intel participate?
- No. Sources explicitly indicate Intel did not release new advisories at the time of publication.
Disclosure coordination among chipmakers remains a signal of maturity, but also a mask: the uniformity of the date is born, the non-uniformity of patching intervals dies. For those operating accelerated infrastructure, September 9 is the start of the work, not the end.
Sources
- https://www.securityweek.com/chipmaker-patch-tuesday-nvidia-amd-arm-issue-security-advisories/
- https://radar.offseq.com/threat/chipmaker-patch-tuesday-nvidia-amd-arm-issue-security-advisories-1ba32375c4965c9b
- https://www.itsecuritynews.info/chipmaker-patch-tuesday-nvidia-amd-arm-issue-security-advisories/
- https://www.cloudlinktech.com/news/patch-tuesday-nvidia-amd-arm-gpu-flaws/
- https://support.arm.com/documentation/111552/1-0/?lang=en
- https://podcast.securityweek.com/
Information has been verified against cited sources and updated at time of publication.
Sources
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.