Impact
The vulnerability occurs when the drm/amdkfd module attempts to restore a CRIU queue without verifying that the restore callback is implemented. If restore_mqd is null and a restore is requested, the kernel performs a NULL pointer dereference that causes a panic, bringing the machine down. A user with CAP_CHECKPOINT_RESTORE can construct a malicious KFD_IOC_CRIU_OP_RESTORE request to trigger this path, resulting in a denial of service. The flaw is a NULL pointer dereference (CWE‑476).
Affected Systems
This flaw is in the Linux kernel drivers for the AMDKFD DRM subsystem, so it applies to all Linux kernel releases that contain this code path. The advisory does not list a specific version range, thus any kernel that has not yet incorporated the NULL guard is susceptible. All distributions shipping the unguarded code are also affected until a patch is applied.
Risk and Exploitability
The EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, indicating low public exploit probability. The required CAP_CHECKPOINT_RESTORE capability limits the attack to local users who already have privileged access, typically root or system services. The attack vector is a local privileged user sending a crafted restore payload; no information suggests that remote code execution is possible. The overall risk is a denial of service if the vulnerability is exploited on a privileged system.
OpenCVE Enrichment
Debian DLA
Debian DSA