Impact
An integer overflow exists in the message bound check of the AMDGPU VCN3 component of the Linux kernel, as identified by the advisory. The flaw could allow a carefully crafted message to bypass the size verification, potentially altering internal kernel state. The official description does not specify the exact consequences, so the impact is limited to the possibility of kernel memory corruption rather than a confirmed exploit. The weakness reflects an unchecked integer overflow. The likely attack vector is local or privileged access to send a crafted message to the GPU driver.
Affected Systems
All Linux kernel environments that contain the AMDGPU VCN3 driver prior to the inclusion of commit db00257ac9e4a51eb2515aaea161a019f7125e10 are affected. No specific vendor, product or version list is supplied, so any kernel with the unpatched driver may be susceptible.
Risk and Exploitability
The EPSS score is <1%, indicating a very low but nonzero exploitation probability. The CVSS score of 7.1 indicates a medium‑to‑high severity level. The flaw is not listed in the CISA KEV catalog. The kernel‑level nature of the flaw indicates a notable risk if exploited. Attackers would need local or privileged access to send messages to the GPU driver. No public exploits are reported, but the possibility for exploitation exists. Based on the description, it is inferred that attackers would require local or privileged access to trigger the overflow, though no public exploitation evidence is currently available.
OpenCVE Enrichment