Impact
A missing signal type check in the dcn401 get_phyd32clk_src function within the drm/amd/display component causes an unhandled memory access when attempting to retrieve the link encoder on a DPIA link, resulting in a kernel crash and a loss of service. This flaw is a local issue that leads only to a denial of service, with no documented ability to execute arbitrary code or elevate privileges beyond the kernel context. The crash disrupts normal operation of the display subsystem, potentially rendering the system unusable until rebooted.
Affected Systems
The vulnerability affects the Linux kernel implementation of DRM for AMD display hardware. All distributions shipping an unpatched kernel that includes the drm/amd/display subsystem are potentially impacted, regardless of the distribution vendor. No specific kernel version or release is listed, so any kernel prior to the patch that incorporates the failing code path is at risk.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, while the EPSS score of < 1% suggests a very low probability of exploitation. The flaw is not listed in the CISA KEV catalog, indicating that no known active exploit exists. A local user with sufficient privileges could trigger the kernel crash by attempting to access the link encoder on a DPIA link, leading to a denial of service that may render the system unusable until rebooted. Overall risk remains moderate and is confined to local denial of service unless other vulnerabilities are chained.
OpenCVE Enrichment