Impact
The vulnerability arises when the AMD kernel mode driver releases an invalid pointer, creating a double free condition. This flaw allows a privileged attacker to manipulate memory management and potentially execute arbitrary code with kernel privileges. The weakness is classified as CWE‑763, indicating improper handling of memory that can lead to code execution.
Affected Systems
The affected products are AMD Radeon Instinct MI25 graphics units and AMD Radeon PRO V620 graphics cards. No specific firmware or driver version information is provided, so all current driver releases for these product lines are potentially impacted.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity. Exploit probability data is not available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires privilege escalation; an attacker must already have administrative or system-level access to trigger the double free and execute code. While the risk is non‑trivial for environments running these drivers, successful exploitation is limited to privileged contexts and no widespread public exploits are reported at this time.
OpenCVE Enrichment