Impact
The Linux kernel’s AMD display driver contains a flaw where the function dml21_add_phantom_plane() is called without verifying that the allocation was successful. If the function fails, the driver later dereferences a null pointer, triggering a kernel segmentation fault that can cause a system-wide crash. This flaw results in a denial of service to all users on the affected system.
Affected Systems
Linux kernels that include the AMD display driver code with the vulnerable path are impacted. The specific kernel versions are not listed, so any kernel containing the identified code could be at risk.
Risk and Exploitability
The EPSS data is unavailable and the vulnerability is not present in the CISA KEV catalog. While the CVSS score is not specified, the nature of the bug—a null pointer dereference in kernel space—suggests a high severity. Exploitation would require local privilege or the ability to trigger the AMD display scenario, making the attack vector likely local rather than remote.
OpenCVE Enrichment