Impact
In the Linux kernel, a race condition exists in the VCN4 subsystem where the interval buffer (IB) parameter length is re‑read instead of reused, allowing the length value to change between the check and the use. This time‑of‑check‑to‑time‑of‑use flaw can lead to inconsistent data handling within the driver, potentially causing unintended behavior.
Affected Systems
The vulnerability is present in all Linux kernel releases that include the VCN4 driver before the commit dbb02b4755f8c1f3773263f2d779872c1c0c073a. Generic kernel builds from major distributions that ship the older driver code are affected. Systems that do not run the VCN4 driver, or are using a kernel version that includes the fix, are not impacted.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity. Exploitation would require precise timing and control over GPU command buffer submission during the race. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, suggesting a low likelihood of widespread exploitation. Based on the description, accidental instability could occur in environments that process untrusted GPU command streams.
OpenCVE Enrichment
Debian DLA