Impact
During a transition state, the AMD DRM driver skips HDCP configuration because the stream context is not yet established. This omission means HDCP protection is not applied when encrypted media is transmitted over HDMI or DisplayPort, potentially allowing unauthorized playback of DRM-protected content or causing playback failures.
Affected Systems
All Linux distributions that ship the Linux kernel with the AMD DRM driver before the patch are vulnerable. The driver is used on AMD GPUs via the amdgpu module, so any kernel release prior to the commit that introduced the fix remains potentially at risk. Version details are not supplied, so all earlier releases remain vulnerable.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, while the EPSS score of <1% signals very low real-world exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local, inferred from the description that an attacker could trigger the transition state by switching display modes or restarting the graphics stack; this exploits the driver’s omission of HDCP configuration during a transient state. Successful exploitation would allow playback of protected content without proper authorization or could disrupt media playback, impacting the confidentiality and availability of DRM content.
OpenCVE Enrichment