Description
In the Linux kernel, the following vulnerability has been resolved:

drm/amd/pm: fix pptable use-after-free

amdgpu_dpm_get_pp_table() returns a pointer to a driver-owned power table
after dropping adev->pm.mutex. The sysfs path then copies from that pointer.
A concurrent pp_table write can replace and free the allocation during the
copy, causing a use-after-free.

Change the DPM interface to copy into caller-provided storage while the mutex
is held. Keep the size-only query for attribute discovery without exposing
the driver-owned pointer.

(cherry picked from commit f6eed7acfd30099ef7baeb6ba45bb59daad80631)
Published: 2026-08-15
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free flaw exists in the AMDGPU DRM driver’s power‑management interface. The function amdgpu_dpm_get_pp_table() returns a pointer to a driver‑owned power table after releasing the pm mutex, and then a sysfs read attempts to copy from that pointer. If a concurrent write frees the table while the copy is taking place, the kernel can read freed memory, leading to corruption. This bug is classified as CWE‑825 and can cause arbitrary kernel memory corruption.

Affected Systems

The vulnerable component is the Linux kernel with the AMDGPU DRM driver. Any kernel version that was shipped prior to the inclusion of commit f6eed7ac (which implements the safe copy into caller‑provided storage) is affected. Distributions that ship an untouched upstream kernel or deploy the kernel without the patch are impacted, while upgraded kernels containing the fix are immune.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity, while the EPSS score of <1% signals a low likelihood of exploitation in the near term. The vulnerability is not listed in the CISA KEV catalog and no public exploits are available. The attack vector, inferred from the description, is local via the sysfs interface that exposes the power table. An attacker who can manipulate the sysfs read might trigger the use‑after‑free, resulting in kernel memory corruption that potentially enables privilege escalation.

Generated by OpenCVE AI on August 22, 2026 at 01:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the amdgpu_dpm_get_pp_table() fix (commit f6eed7ac).
  • Reboot the system to load the updated kernel and the patched AMDGPU driver module.
  • Disable the sysfs attribute that exposes the power table until the kernel patch is applied.

Generated by OpenCVE AI on August 22, 2026 at 01:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6466-1 linux security update
History

Sun, 23 Aug 2026 13:15:00 +0000


Sat, 22 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Thu, 20 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 17 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Mon, 17 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 15 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm/amd/pm: fix pptable use-after-free amdgpu_dpm_get_pp_table() returns a pointer to a driver-owned power table after dropping adev->pm.mutex. The sysfs path then copies from that pointer. A concurrent pp_table write can replace and free the allocation during the copy, causing a use-after-free. Change the DPM interface to copy into caller-provided storage while the mutex is held. Keep the size-only query for attribute discovery without exposing the driver-owned pointer. (cherry picked from commit f6eed7acfd30099ef7baeb6ba45bb59daad80631)
Title drm/amd/pm: fix pptable use-after-free
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-23T12:47:19.009Z

Reserved: 2026-08-15T05:44:03.899Z

Link: CVE-2026-74450

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T13:17:49.593

Modified: 2026-08-23T13:16:43.837

Link: CVE-2026-74450

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-74450 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T01:30:17Z

Weaknesses
  • CWE-825

    Expired Pointer Dereference