Impact
The vulnerability lies in the AMDGPU driver within the Linux kernel, where the notifier sequence was inadvertently read more than once, potentially causing the driver to operate on invalid memory pages. This flaw could lead to kernel memory corruption if the double‑read path is exercised. The description does not claim privilege escalation, only that corrupted memory may arise during normal driver operation.
Affected Systems
The defect is likely present in Linux kernel releases that included the AMDGPU DRM module before the commit c08972f555945cda57b0adb72272a37910153390. Systems running unpatched kernels with the AMDGPU driver, regardless of distribution, may be affected, but the exact scope is inferred from the commit history and given advisories.
Risk and Exploitability
The CVSS score of 7.8 denotes high severity; however, the EPSS score of less than 1% indicates that exploitation likelihood is very low at present, and the vulnerability is not listed in the CISA KEV catalog. A likely attack would require interaction with the AMDGPU driver, possibly through GPU workloads or operations that trigger the notifier sequence. The attack vector is inferred to be local or user‑initiated GPU activity and does not appear to involve remote exploitation.
OpenCVE Enrichment
Ubuntu USN