Impact
The vulnerability allows users with access to the /dev/kfd device to terminate another process's GPU debug session without verifying session ownership or requiring ptrace authorization. This missing authorization check enables malicious or misconfigured local users to disrupt active debugging operations, causing denial of service to debugging activities.
Affected Systems
The flaw exists in the Linux kernel DRM KFD subsystem and affects all kernel versions that lack the corresponding patch. The affected product is the Linux kernel, with no specific downstream version information provided in the data.
Risk and Exploitability
The vulnerability is a local issue exploitable by any user with write access to the /dev/kfd device. EPSS is not available and the issue is not listed in CISA KEV. The exploit requires only that the attacker has write access to the /dev/kfd character device, which is typically granted to privileged users; thus the risk is significant for environments that permit unrestricted access to this device.
OpenCVE Enrichment