[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fe9YR_qNlj4CKx58aF5ZZIL_d0VHYhI-QxKgYF5M4NeY":3},{"article":4,"iocs":43},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":30,"category":31,"article_tags":35},"be20c53c-2b4a-4f8f-8fff-1afac9e89b76","Chipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security Advisories","chipmaker-patch-tuesday-nvidia-amd-arm-issue-security-advisories-de29ff","Major chipmakers announced patches for vulnerabilities recently discovered in their products. The post Chipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security Advisories appeared first on SecurityWeek.","Major chip manufacturers AMD, Arm, and Nvidia have issued security advisories detailing recently discovered vulnerabilities in their products. AMD has addressed a NULL pointer dereference flaw in its Linux GPU kernel driver, while Arm has released fixes for nine vulnerabilities affecting its Mali GPUs. Nvidia has also released an update for its Triton Inference Server to resolve two high-severity security defects.","Nvidia, AMD, and Arm have released security advisories detailing new vulnerabilities.","Major chipmakers AMD, Arm, and Nvidia published new security advisories on Tuesday to notify customers of vulnerabilities recently discovered in their products. AMD announced fixes for CVE-2026-43603, a NULL pointer dereference flaw in its Linux GPU kernel driver that could lead to system crashes and a denial-of-service (DoS) condition. The company credited Maxime Rossi Bellom and Ramtine Tofighi Shirazi from SecMate for reporting the security defect. “According to the researchers’ report, when an application invokes a specific graphics memory management interface to perform a ‘clear’ operation under certain compute-processing conditions, the driver may fail to validate an internal data reference before use,” AMD notes in its advisory. The company rolled out fixes for EPYC Athlon, Ryzen, Radeon, and Instinct processors in July. It plans to release the patches for the EPYC Embedded and Ryzen Embedded processors in October. Arm published an advisory covering nine vulnerabilities in its Mali GPUs that could allow access to already freed memory or to sensitive kernel information, or could lead to a denial-of-service (DoS) condition.Advertisement. Scroll to continue reading. The company has released fixes for the Valhall GPU and Arm 5th Gen GPU Architecture kernel and userspace drivers. The Bifrost GPU kernel and userspace drivers are also affected. Nvidia announced a software update for the Triton Inference Server for Linux that resolves two high-severity security defects. The first could lead to a DoS condition, while the second could lead to information disclosure, data tampering, and DoS conditions. At the time of publishing, Intel had not released new security advisories since the previous Patch Tuesday. Related: ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws Related: Ivanti Patches Critical Flaws Across Enterprise Security Products Related: Chrome 153 Patches Seventh Zero-Day of 2026 Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Chrome 153 Patches Seventh Zero-Day of 2026Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-DaysAdobe Patches Over 170 Vulnerabilities, Including Commerce Zero-DayHackers Return $263 Million Stolen From Liquid NetworkSAP Patches Critical Extended Passport Processing VulnerabilityMikroTik Patches Critical Flaws Chained to Hack RoutersMathspace Data Breach Exposes Over 1 Million PeopleN-able Patches Critical Zero-Day in N-central Latest News HelmGuard Raises $7.3 Million for Agentic GRC and SecurityAI Is Giving Lesser-Resourced Attackers Nation-State-Level Reach, Google WarnsAndroid’s September 2026 Updates Patch 180 VulnerabilitiesFortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome ExtensionUS Agencies Warn China Is Systematically Extracting Frontier AI CapabilitiesMeta Launches Personal AI Agent, Muse, Emphasizes Safety and PrivacyICS Patch Tuesday: Schneider Electric, Siemens Fix Critical FlawsIvanti Patches Critical Flaws Across Enterprise Security Products Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveFrank Verdecanna has been appointed Chief Financial Officer at Armadin.Keeper Security has named Jessica Krowel and Bill Grabner as SVPs of sales for North America.Skyhigh Security has named Anthony Palladino as Chief Operating Officer.More People On The MoveExpert Insights This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, \"data\" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Fchipmaker-patch-tuesday-nvidia-amd-arm-issue-security-advisories\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2023\u002F01\u002FCybersecurity_News-SecurityWeek.jpg","2026-09-09T16:22:54+00:00","2026-09-09T18:00:09.809943+00:00",7,[18,21,23,25,28],{"name":19,"type":20},"AMD","vendor",{"name":22,"type":20},"Arm",{"name":24,"type":20},"Nvidia",{"name":26,"type":27},"Mali GPUs","product",{"name":29,"type":27},"Triton Inference Server","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":30,"icon":32,"name":33,"slug":34},null,"Vulnerabilities","vulnerabilities",[36,38],{"category":37},{"id":30,"icon":32,"name":33,"slug":34},{"category":39},{"id":40,"icon":32,"name":41,"slug":42},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[44],{"type":45,"value":46,"context":47},"cve","CVE-2026-43603","NULL pointer dereference flaw in AMD's Linux GPU kernel driver"]