Impact
The vulnerability occurs in the Linux kernel's AMD KFD driver when a VM range contains a hole on the CPU side; the driver allocates device pages without a proper DMA map and uses an uninitialized variable in the migration copy routine. This leads to a call that can drop all VRAM previously allocated, effectively destroying graphics memory resources. The flaw can therefore result in a denial‑of‑service condition for any process relying on the kernel’s graphics memory allocation. The weakness is rooted in the use of an uninitialized variable.
Affected Systems
It affects Linux kernel releases that include the drm/amdkfd module before the patch identified by commit 0a9a0e8a97da70a0336c9115178aaf1be29bcfb1. The specific kernel versions are not enumerated in the advisory, but all kernels with AMD KFD DRM support prior to the fix are potentially affected.
Risk and Exploitability
The CVSS score of 7.8 classifies the issue as high severity. The EPSS score of less than 1% indicates that exploitation probability is currently very low. The vulnerability is not listed in CISA’s KEV catalog, suggesting no known public exploitation. The attack vector would likely require privileged kernel context or the ability to trigger a migration of a VM range with a hole; an attacker could induce the problematic scenario either through a crafted application that uses KFD or by leveraging an existing privileged process. If successfully exploited, the vulnerability could lead to drastic loss of VRAM and instability of GPU‑dependent workloads.
OpenCVE Enrichment